--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/f75cd7b3-6ef7-4600-9989-b751216546b6%40googlegroups.com.
Are you running any non-default Zeek scripts?
From your post on the Zeek mailing list, it looks like you're using AF_PACKET. Have you tried switching to PF_RING to see if that makes any difference at all?
Are you running netsniff-ng? If so, can you verify that it is running with the --no-hwtimestamp option?
Are you logging in TSV or JSON format? Have you tried switching that format to see if it makes any difference at all?
Are you able to share a full sostat?
Thanks for checking, Doug.
On Sunday, 23 February 2020 20:57:13 UTC, Doug Burks wrote:Are you running any non-default Zeek scripts?I've enabled intel and frameworks/intel/whitelist, and disabled MHR. No custom scripts.From your post on the Zeek mailing list, it looks like you're using AF_PACKET. Have you tried switching to PF_RING to see if that makes any difference at all?I am using AF_PACKET. I have not tried switching to PF_RING. Is there a guide on how to do that?
Are you running netsniff-ng? If so, can you verify that it is running with the --no-hwtimestamp option?I am running netsniff-ng. A ps listing shows it is running with --no-hwtimestamp.
Are you logging in TSV or JSON format? Have you tried switching that format to see if it makes any difference at all?I'm logging to JSON. If I switch to TSV, logstash loses the ability to import into Elastic, doesn't it?
Are you able to share a full sostat?I'll see about getting that together this week This is an install done by loading Ubuntu Server, adding your repo, and installing securityonion-[sensor,server,elastic]. It is running a few other python scripts and docker images.
----Pete
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/f4a1ba16-71bd-464a-a5f4-761c8479ac9e%40googlegroups.com.
--
Pete
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAAYFXL%3Dvncss8Hz8yU%3DiiR6NjZ_ws9D1tpHOgx6Le8iFZhfqJA%40mail.gmail.com.
On Mon, Feb 24, 2020 at 9:20 AM Pete Nelson <peti...@gmail.com> wrote:
> > Off the top of my head, it should be something like:
> > sudo so-zeek-stop
> > Edit /opt/zeek/etc/node.cfg and change lb_method=custom to lb_method=pf_ring
> > sudo so-zeek-start
>
> Thank you. I'll give that a shot. We have spare CPU/RAM and
> relatively low packet rate, so PF_RING should have no trouble keeping
> up.
I was hopeful this would be a solution, but within minutes, I had one
process back up at 102% again (100 on the main thread and a little on
a couple of the others).. If anything, it might be happening sooner
using pf_ring.
I'll wait a bit to see if Justin responds before I start fiddling with
other areas. IThanks for confirming, Pete. At least we can eliminate the AF_PACKET plugin as a possible culprit.Sounds like Justin knows where the issue is. If you guys are able to convince him that it is indeed a bug, then perhaps they can fix it and release Zeek 3.0.2?
--
Pete
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to securit...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAAYFXL%3Dvncss8Hz8yU%3DiiR6NjZ_ws9D1tpHOgx6Le8iFZhfqJA%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/7879d62c-e375-4a0d-989e-6e70281d08ae%40googlegroups.com.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAAYFXLkQX4gAwGooj3SYkU4oN60Y4KeMQpm4Utt%2BtVJEfbNaPQ%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to securit...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAAYFXLkQX4gAwGooj3SYkU4oN60Y4KeMQpm4Utt%2BtVJEfbNaPQ%40mail.gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/10038209-7828-4e62-b204-61ee280ad7a4%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAKHG%3D-Jm8a3FsCNExQqeKMVbiBnHucD8bwRv2wx92vusm9Shrw%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/CAJ%2BhwWCf-dRY11_HjrndrmBEzLckH5q%2B-ecFw1K_5BXzJdDSNQ%40mail.gmail.com.
Had I not read your test suggestion, I would not have noticed we had both running at the same time.
Choosing the one that was already working has resolved my version of the issue. :-)
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/347a6795-60a2-49a9-993d-25aee657ffb6%40googlegroups.com.
Zeek 3.0.3 now available for Security Onion!
On Thu, Mar 12, 2020 at 3:49 PM Doug Burks <doug...@securityonionsolutions.com> wrote:
Thanks for the update, Pete!
On Thu, Mar 12, 2020 at 3:36 PM Pete <peti...@gmail.com> wrote:
Steven Malm and Steven J,--I wanted to make sure you don't misunderstand what's going on here. The fix is not setting the lb_method. I have personally seen the CPU load peg using both AF_PACKET and PF_RING. It may appear you've fixed it, but what you're seeing is just due to zeek being restarted; without the version upgrade, it is likely to come back after some time.The fix is coming in Zeek v3.0.3 in the form of a code update in the broker package.Doug, I've been running v3.0.3 on one system for close to a day, and haven't seen the issue. I'm going to test on another system or two, but so far it looks good. I haven't tried any other variants as described in the testing procedure, however.I'll give another update tomorrow.--Pete
On Thursday, 12 March 2020 14:25:33 UTC-4, Steven Malm wrote:
Had I not read your test suggestion, I would not have noticed we had both running at the same time.
Choosing the one that was already working has resolved my version of the issue. :-)On Thu, Mar 12, 2020 at 10:48 AM 'Steven J' via security-onion <securit...@googlegroups.com> wrote:Setting method to pf_ring has put my cpu consumption back to the 12-34% range. :-)I was already running pf_ring for my 4 workers and somebody snuck this one in when I wasn't looking.@Doug Burks, thank you for:
' Edit /opt/zeek/etc/node.cfg and change lb_method=custom to lb_method=pf_ring 'Sjm
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to securit...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/security-onion/347a6795-60a2-49a9-993d-25aee657ffb6%40googlegroups.com.
--Doug Burks
CEO
Security Onion Solutions, LLC