This is in cronlog around that time. Could nsm_sensor_clean be causing it?
Dec 13 11:58:01 so-forward CRON[14765]: (root) CMD (/usr/sbin/so-netsniff-ng-cron > /dev/null 2>&1)
Dec 13 11:59:01 so-forward CRON[14817]: (root) CMD ( /usr/sbin/so-nsm-watchdog >> /var/log/nsm/watchdog.log 2>&1)
Dec 13 11:59:01 so-forward CRON[14818]: (root) CMD (/usr/sbin/so-netsniff-ng-cron > /dev/null 2>&1) Dec 13 11:59:01 so-forward CRON[14819]: (root) CMD (find /var/www/so/capme/pcap/*.pcap -mmin +1440 -delete >/dev/null
2>&1) Dec 13 11:59:01 so-forward CRON[14820]: (root) CMD (/usr/sbin/nsm_sensor_clean -y >> /var/log/nsm/sensor-clean.log 2>&
1)
Dec 13 12:00:01 so-forward CRON[16413]: (root) CMD (/usr/sbin/so-bro-cron >> /var/log/nsm/so-bro-cron.log 2>&1)
Dec 13 12:00:01 so-forward CRON[16414]: (root) CMD (/usr/sbin/nsm_sensor_ps-restart --only-sancp-agent >/dev/null) Dec 13 12:00:01 so-forward CRON[16415]: (root) CMD (/usr/bin/salt-call state.highstate >/dev/null 2>&1)
Dec 13 12:00:01 so-forward CRON[16417]: (root) CMD (/usr/sbin/nsm_sensor_clean -y >> /var/log/nsm/sensor-clean.log 2>&1)
Dec 13 12:00:01 so-forward CRON[16416]: (root) CMD (/usr/sbin/so-netsniff-ng-cron > /dev/null 2>&1) Dec 13 12:00:01 so-forward CRON[16418]: (root) CMD (/usr/sbin/so-squert-ip2c-5min > /dev/null 2>&1)
Dec 13 12:00:01 so-forward CRON[16419]: (root) CMD (find /var/www/so/capme/pcap/*.pcap -mmin +1440 -delete >/dev/null 2>&1)
Dec 13 12:01:01 so-forward CRON[16952]: (root) CMD (find /var/www/so/capme/pcap/*.pcap -mmin +1440 -delete >/dev/null
2>&1)
Dec 13 12:01:01 so-forward CRON[16953]: (root) CMD (/usr/sbin/so-netsniff-ng-cron > /dev/null 2>&1)
Dec 13 12:01:01 so-forward CRON[16954]: (root) CMD (/usr/sbin/nsm_sensor_ps-restart --only-http-agent >/dev/null)
Dec 13 12:01:01 so-forward CRON[16955]: (root) CMD (/usr/sbin/nsm_sensor_clean -y >> /var/log/nsm/sensor-clean.log 2>&1)
I notice barnyard processing might be a bit slow, if I'm reading it right. At the moment barnyard2.log tells me it opened spool file snort.unified2.1576233377, and the latest unified2 file is snort.unified2.1576244730. It's been like that for some time. There are about 10 other files between them. Server has enough processing power and memory. Is that cause for concern?
If I restart with so-sensor-restart, I can immediately see alerts being processed in snort_agent.log.