- local_internal_options.conf (new, bind-mounted): increase analysisd queue sizes 16384→65536 for decode/archives/alerts to absorb FortiGate syslog bursts that were causing "Input queue is full" warnings; set event_threads=4, rule_matching_threads=4, dbsync_threads=2 on 12-CPU host; state_interval 5s→30s to reduce I/O. - docker-compose.yml: add bind-mount for local_internal_options.conf. - soc-a4/soc-c1-c3 rules: fix T1098.007→T1098 (sub-technique not in Wazuh 4.14 MITRE DB; was logging WARNING on every group membership event). Result: events_dropped=0; queue overflow warnings eliminated. Note: ~4500 EPS from FortiGate syslog is the root CPU driver — disable logall=yes in wazuh_manager.conf to reduce further if archive replay is no longer needed. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
||
| 1 |
|
|
| 2 |
|
|
| 3 |
|
|
| 4 |
|
|
| 5 |
|
|
| 6 |
|
|
| 7 |
|
|
| 8 |
|
|
| 9 |
|
|
| 10 |
|
|
| 11 |
|
|
| 12 |
|
|
| 13 |
|
|
| 14 |
|
|
| 15 |
|
|
| 16 |
|
|
| 17 |
|
|
| 18 |
|
|
| 19 |
|
|
| 20 |
|
|
| 21 |
|
|
|
||
| 130 | 130 |
|
| 131 | 131 |
|
| 132 | 132 |
|
| 133 |
|
|
| 133 |
|
|
| 134 | 134 |
|
| 135 | 135 |
|
| 136 | 136 |
|
|
||
| 138 | 138 |
|
| 139 | 139 |
|
| 140 | 140 |
|
| 141 |
|
|
| 141 |
|
|
| 142 | 142 |
|
| 143 | 143 |
|
| 144 | 144 |
|
|
||
| 86 | 86 |
|
| 87 | 87 |
|
| 88 | 88 |
|
| 89 |
|
|
| 89 |
|
|
| 90 | 90 |
|
| 91 | 91 |
|
| 92 | 92 |
|
|
||
| 52 | 52 |
|
| 53 | 53 |
|
| 54 | 54 |
|
| 55 |
|
|
| 55 | 56 |
|
| 56 | 57 |
|
| 57 | 58 |
|