Skip to content
Discussion options

You must be logged in to vote

From https://docs.securityonion.net/en/2.3/architecture.html#distributed:

If you install a dedicated manager node, you must also deploy one or more search nodes. Otherwise, all logs will queue on the manager and have no place to be stored. If you are limited on the number of nodes you can deploy, you can install a manager search node so that your manager node can act as a search node and store those logs. However, please keep in mind that overall performance and scalability of a manager search node will be lower compared to our recommended architecture of dedicated manager node and separate search nodes.

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
2 replies
@grakesh-061
Comment options

@grakesh-061
Comment options

Answer selected by dougburks
Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants