- local_internal_options.conf (new, bind-mounted): increase analysisd queue sizes 16384→65536 for decode/archives/alerts to absorb FortiGate syslog bursts that were causing "Input queue is full" warnings; set event_threads=4, rule_matching_threads=4, dbsync_threads=2 on 12-CPU host; state_interval 5s→30s to reduce I/O. - docker-compose.yml: add bind-mount for local_internal_options.conf. - soc-a4/soc-c1-c3 rules: fix T1098.007→T1098 (sub-technique not in Wazuh 4.14 MITRE DB; was logging WARNING on every group membership event). Result: events_dropped=0; queue overflow warnings eliminated. Note: ~4500 EPS from FortiGate syslog is the root CPU driver — disable logall=yes in wazuh_manager.conf to reduce further if archive replay is no longer needed. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
|
||
|
1 |
|
|
|
2 |
|
|
|
3 |
|
|
|
4 |
|
|
|
5 |
|
|
|
6 |
|
|
|
7 |
|
|
|
8 |
|
|
|
9 |
|
|
|
10 |
|
|
|
11 |
|
|
|
12 |
|
|
|
13 |
|
|
|
14 |
|
|
|
15 |
|
|
|
16 |
|
|
|
17 |
|
|
|
18 |
|
|
|
19 |
|
|
|
20 |
|
|
|
21 |
|
|
|
||
| 130 |
|
130 |
|
| 131 |
|
131 |
|
| 132 |
|
132 |
|
| 133 |
|
|
|
|
133 |
|
|
| 134 |
|
134 |
|
| 135 |
|
135 |
|
| 136 |
|
136 |
|
|
|
||
| 138 |
|
138 |
|
| 139 |
|
139 |
|
| 140 |
|
140 |
|
| 141 |
|
|
|
|
141 |
|
|
| 142 |
|
142 |
|
| 143 |
|
143 |
|
| 144 |
|
144 |
|
|
|
||
| 86 |
|
86 |
|
| 87 |
|
87 |
|
| 88 |
|
88 |
|
| 89 |
|
|
|
|
89 |
|
|
| 90 |
|
90 |
|
| 91 |
|
91 |
|
| 92 |
|
92 |
|
|
|
||
| 52 |
|
52 |
|
| 53 |
|
53 |
|
| 54 |
|
54 |
|
|
55 |
|
|
| 55 |
|
56 |
|
| 56 |
|
57 |
|
| 57 |
|
58 |
|