Skip to content
Discussion options

You must be logged in to vote

I have a distributed sec deployment. One manager node, one search, and one sensor. I have it on a vsan

For best results, we typically recommend direct dedicated storage to avoid I/O contention (especially for processes like stenographer):
https://docs.securityonion.net/en/2.3/hardware.html#storage
https://docs.securityonion.net/en/2.3/best-practices.html#installation

every time I run tcpreplay with more then 1gb I get 30% stenographer packet loss and 1.40% suricata packet loss. Does anyone know how I can fix this?

Are you using tcpreplay to simulate your anticipated network traffic in production? If so, then just because you get packet loss during tcpreplay does not necessarily mean t…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by vvenom61991
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants