Hi Team,
I’m experiencing an issue with my Wazuh cluster setup where the Wazuh-Analysisd daemon is consuming lots of CPU resource, leading to a heavy load on my servers. Due to this many events are getting dropped, and the process is spending 11+ hours on the queue.
Here are the server specs:
The Average EPS is around 349.926, yet the system is struggling to keep up. I have attached Htop screenshots, along with the wazuh-analysisd_state and statistics images for both servers.
Any insights or suggestions on how to resolve this and optimize the performance would be greatly appreciated! Please help me on this.
Thanks,