--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
Thank you very much for the support to all, if that manages to see, that 90% of disk use did not happen, it eliminates them. I create a cronjob to eliminate it every minute, because it stores up to 28 or 30 logs, and eliminates the first, I think it did not help much.
By the way version 16.04 is excellent.
Regards,
Thank you very much for the support, I was considering the idea of creating a separate disk to store those logs (even if they are in binary), in the same way I do not think it affects the performance of the sensor.
Regards,
Once installed, I then wrote a simple shell script to fire off once daily via cron - keeps my PCAPs from getting out of control.
If my scenario is the same as yours, I thought about creating another virtual machine to store the logs there and on the side of the NSM leave everything without low performance.
Thank you for your comments.
That said, I'm not really sure what another dedicated VM provides. If concerned about CPU, RAM, etc., then I think you can get more bang for your buck by adding the resources you would use for the 2nd VM to your original SO VM...again, just my opinion. I'm sure others will have comments as well...
Well, I had two scenarios, but I think it would be better to add a partition to the SO virtual machine, what do you recommend?
If the former, that will definitely help on the storage space issue and may help with performance.
But if the latter, I'm not sure what a dedicated partition on the same disk that's already being used will provide except possibly more complexity...
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.