Hello Wazuh Support Team,
I am reaching out to request your guidance regarding some warnings we are experiencing in our current Wazuh deployment.
We are running a single-node installation on Ubuntu 24.04, with 12 CPU cores, 32 GB RAM, and 1.5 TB of disk. The environment currently manages around 700 active agents, and our EPS rate is approximately 1,800.
Recently, we have observed the following warnings in the logs:
Additionally, based on the Wazuh statistics, we are seeing dropped events:
analysisd stats:
remoted queue stats:
Given these metrics and warnings, I would like to confirm:
Are these issues related to the current hardware limitations of my single-node setup?
Would you recommend migrating to a multi-node cluster architecture to properly support 700 agents and prevent event loss?
If so, could you please provide hardware sizing guidelines (CPU, RAM, disk) that would be suitable for both the current 700 agents and for future scalability up to 2,000 agents?
Thank you very much for your support and for helping us identify the best approach to stabilize and scale our environment.
Best regards.