Hello,
I am running a Wazuh cluster and in my cluster there are 4 manager, 3 indexer and 1 dashboard nodes and approximately 1900 Windows agents connected through a load balancer.
Each manager node has a /var/ossec/queue/db directory, and this directory is continuously growing on all nodes. Currently, each /db folder is already around 90–95 GB and keeps increasing over time, eventually filling up the storage.
Could you please help clarify:
Any guidance or best practices for managing storage usage in this scenario would be appreciated.
Thank you.