root@rumosvlzwzhap:/var/ossec/etc# grep -i "oom\|killed" /var/log/syslog /var/log/kern.log
/var/log/syslog:Sep 24 06:06:00 rumosvlzwzhap systemd[1]: system.slice: A process of this unit has been killed by the OOM killer.
/var/log/syslog:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.167766] kworker/2:0 invoked oom-killer: gfp_mask=0xdc0(GFP_KERNEL|__GFP_ZERO), order=0, oom_score_adj=0
/var/log/syslog:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.167859] oom_kill_process.cold+0xb/0x10
/var/log/syslog:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.168308] [ pid ] uid tgid total_vm rss pgtables_bytes swapents oom_score_adj name
/var/log/syslog:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.168446] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=/,mems_allowed=0,global_oom,task_memcg=/system.slice/wazuh-manager.service,task=wazuh-analysisd,pid=2393620,uid=115
/var/log/syslog:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.168537] Out of memory: Killed process 2393620 (wazuh-analysisd) total-vm:17287696kB, anon-rss:13092084kB, file-rss:0kB, shmem-rss:0kB, UID:115 pgtables:29812kB oom_score_adj:0
/var/log/syslog:Sep 25 05:07:33 rumosvlzwzhap systemd[1]: wazuh-manager.service: A process of this unit has been killed by the OOM killer.
/var/log/syslog:Sep 25 05:07:34 rumosvlzwzhap kernel: [9136483.200424] oom_reaper: reaped process 2393620 (wazuh-analysisd), now anon-rss:0kB, file-rss:0kB, shmem-rss:0kB
/var/log/syslog:Sep 25 05:07:40 rumosvlzwzhap systemd[1]: wazuh-manager.service: Failed with result 'oom-kill'.
/var/log/kern.log:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.167766] kworker/2:0 invoked oom-killer: gfp_mask=0xdc0(GFP_KERNEL|__GFP_ZERO), order=0, oom_score_adj=0
/var/log/kern.log:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.167859] oom_kill_process.cold+0xb/0x10
/var/log/kern.log:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.168308] [ pid ] uid tgid total_vm rss pgtables_bytes swapents oom_score_adj name
/var/log/kern.log:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.168446] oom-kill:constraint=CONSTRAINT_NONE,nodemask=(null),cpuset=/,mems_allowed=0,global_oom,task_memcg=/system.slice/wazuh-manager.service,task=wazuh-analysisd,pid=2393620,uid=115
/var/log/kern.log:Sep 25 05:07:32 rumosvlzwzhap kernel: [9136480.168537] Out of memory: Killed process 2393620 (wazuh-analysisd) total-vm:17287696kB, anon-rss:13092084kB, file-rss:0kB, shmem-rss:0kB, UID:115 pgtables:29812kB oom_score_adj:0
/var/log/kern.log:Sep 25 05:07:34 rumosvlzwzhap kernel: [9136483.200424] oom_reaper: reaped process 2393620 (wazuh-analysisd), now anon-rss:0kB, file-rss:0kB, shmem-rss:0kB
We use a distributed structure, with 16GB of RAM available on the server with the manager role.
Manager information:
Version v4.10.1
Installation path /var/ossec
Installation type server
Agents 40
We also send logs from Kaspersky Security Center via syslog to Wazuh.
There are no dropped events in wazuh-analysisd.state, I removed all the custom rules, but RAM consumption continued to grow (I didn't wait for it to be fully filled, because this one will take 7 days).
Ossec log:
2025/09/24 04:07:20 wazuh-modulesd:content-updater: WARNING: Couldn't run full content download: Error -1 from server: Timeout was reached.
2025/09/24 04:11:42 wazuh-modulesd:content-updater: WARNING: Offset processing failed. Triggered a snapshot download.
2025/09/24 04:16:04 wazuh-modulesd:content-updater: WARNING: Couldn't run full content download: Error -1 from server: Timeout was reached.
2025/09/24 04:20:26 wazuh-modulesd:content-updater: ERROR: Action for 'vulnerability_feed_manager' failed: Error -1 from server: Timeout was reached.
2025/09/24 04:57:23 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2025/09/24 04:57:30 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2025/09/24 05:24:46 wazuh-modulesd:content-updater: WARNING: Couldn't run full content download: Error -1 from server: Timeout was reached.
2025/09/24 05:29:09 wazuh-modulesd:content-updater: WARNING: Offset processing failed. Triggered a snapshot download.
2025/09/24 05:33:31 wazuh-modulesd:content-updater: WARNING: Couldn't run full content download: Error -1 from server: Timeout was reached.
2025/09/24 05:37:53 wazuh-modulesd:content-updater: ERROR: Action for 'vulnerability_feed_manager' failed: Error -1 from server: Timeout was reached.
2025/09/24 05:57:31 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2025/09/24 05:57:39 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2025/09/24 06:42:13 wazuh-modulesd:content-updater: WARNING: Couldn't run full content download: Error -1 from server: Timeout was reached.
2025/09/24 06:46:35 wazuh-modulesd:content-updater: WARNING: Offset processing failed. Triggered a snapshot download.
2025/09/24 06:50:58 wazuh-modulesd:content-updater: WARNING: Couldn't run full content download: Error -1 from server: Timeout was reached.
2025/09/24 06:55:20 wazuh-modulesd:content-updater: ERROR: Action for 'vulnerability_feed_manager' failed: Error -1 from server: Timeout was reached.
Also I attach screenshot of available memory and swap.
I will be glad of any help.
BR,
Mikhail Glebov