-
HI, I am running the latest SO built ( 2.3.90) . I have recently noticed that my /nsm/zeek/spool/tmp is filling up with crash logs. I have checked one post-terminate-logger-2021-12-16-07-12-30-78-crash/post-terminate.out file its has a message send-mail: /usr/sbin/sendmail not found Also many other folders have zeek logs too. I would appreciate it if someone can help me fix the issue. Thanks |
Beta Was this translation helpful? Give feedback.
Replies: 11 comments 7 replies
-
On our systems zeek proccess crashes happen quite often with low ram sensors.. |
Beta Was this translation helpful? Give feedback.
-
I don't think RAM is an issue with my box. I have almost 300Gb Thanks |
Beta Was this translation helpful? Give feedback.
-
I'm not seeing this issue on any of my systems. @zpravaiz please provide more information about your system and configuration including:
|
Beta Was this translation helpful? Give feedback.
-
Hi Doug,
I am running this box for a very long time. The purpose is just to record & monitor the activity on the network. I am not ingesting anything in elastic too. I store Zeek and Suricata logs and use the command line whenever needed. I notice this issue when the disk is filling up quickly. Do let me know if you need further information. I appreciate your help. Best Update: root@so-main:/nsm/zeek/spool/tmp# cat post-terminate-logger-2021-12-18-18-12-10-8842/stderr.log root@so-main:/nsm/zeek/spool/tmp# ls -a post-terminate-logger-2021-12-18-18-12-10-8842/ Hope this may help. |
Beta Was this translation helpful? Give feedback.
-
Hi All, I would appreciate it if anyone can share some pointers to resolve this issue. Thanks |
Beta Was this translation helpful? Give feedback.
-
What is the output of |
Beta Was this translation helpful? Give feedback.
-
Hi Doug, See the below. Space is not an issue. I have 3.5T free space. root@so-main:/nsm/zeek/spool/tmp# df -h |
Beta Was this translation helpful? Give feedback.
-
If you haven't already, I would go ahead and upgrade to Security Onion 2.3.91 and reboot the box. If the crashes continue, you might look for any non-standard traffic on your network that might be causing Zeek to crash. You could also try switching from Zeek metadata to Suricata metadata: |
Beta Was this translation helpful? Give feedback.
-
Doug,
I did so but still, the problem did not resolve. I really like Zeek and my all scrips are built around that. It would be great if this problem gets resolved. |
Beta Was this translation helpful? Give feedback.
-
HI Dough, an update. I noticed post-terminate-logger crash was happening every hour. This reminds me OTX gets updated every hour by the zeek_otx.py. I disabled the cron job for /usr/sbin/zeek_otx.py and now the crash is not happening anymore since yesterday. can you please suggest what could be the issue with OTX.dat file? I would appreciate your help. Thanks |
Beta Was this translation helpful? Give feedback.
-
We already had a warning at https://docs.securityonion.net/en/2.3/alienvault-otx.html that we don't officially support OTX integration, but I've also added a warning that it may cause Zeek crashes. |
Beta Was this translation helpful? Give feedback.
We already had a warning at https://docs.securityonion.net/en/2.3/alienvault-otx.html that we don't officially support OTX integration, but I've also added a warning that it may cause Zeek crashes.