Low nsm partition usage #14148
-
Version2.4.111 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM64 Storage for /280GB Storage for /nsm8TB Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailAfter 21 days of activity with an average traffic of 40Mb/s I have a NSM partition utilization of 29% with a PCAP retention of just 3 days. All system settings are at the default values. What could be the cause of the problem? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 7 replies
-
Do you think you should have more disk usage? What do your indices look like? If you look in influxdb, what is your PCAP retention? |
Beta Was this translation helpful? Give feedback.
-
What is the setting at Administration > Configuration > global > pcapengine? |
Beta Was this translation helpful? Give feedback.
-
Current Grid Value: 25 |
Beta Was this translation helpful? Give feedback.
OK, so what is the setting at Administration > Configuration > suricata > pcap > maxsize?