-
Version2.4.170 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU80 RAM350 Gb Storage for /238 Gb Storage for /nsm9596 Gb Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi everyone, We've noticed a significant Capture Loss issue on our Security Onion instance and are hoping you can help us figure out the cause. The problem: Our setup and what we've already tried: The SPAN port is configured on a high-performance core switch. The cabling has been checked and replaced multiple times. Physical network card (NIC) offloading has been disabled. The server hardware seems to be well-provisioned, with no obvious bottlenecks in terms of CPU, RAM, or disk. This high loss rate is making our analysis difficult. Do you have any suggestions on what we should check or what configurations we could optimize to solve this issue? Thanks in advance for your help! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
Is this a physical machine or VM? What model NIC are you using? What is the output of the following (replacing
|
Beta Was this translation helpful? Give feedback.
Please try the following and see if it helps: