Here is a thread on some performance tests that I ran on OSSEC
http://groups.google.com/group/ossec-list/browse_thread/thread/224408b3f6b034a8/f758743dacf7ed72?lnk=gst&q=performance+testing#f758743dacf7ed72

<http://groups.google.com/group/ossec-list/browse_thread/thread/224408b3f6b034a8/f758743dacf7ed72?lnk=gst&q=performance+testing#f758743dacf7ed72>I
found that ossec took approx 65%-70% CPU at 11,000 EPS.  The test setup
max'd out at 14000 EPS.  I was testing on a 2 CPU, 4 GB RAM VM (which is not
even as good as a Core Duo Intel desktop CPU)


On Sat, Jan 8, 2011 at 12:37 PM, jplee3 <[email protected]> wrote:

> Hi all,
>
> We experienced 90%+ utliziation from the ossec-agentd on a couple
> servers this morning and I was able to trace it to a log file that
> grew extremely large in a relatively short time window (1gb of growth
> within a 2-3 hour time window). After removing the log for OSSEC to
> monitor, agentd quieted down. Prior to this the systems were almost to
> the point of being hosed. This is on Linux btw. I read an article
> mentioning excessive # of events at least in Windows will be the
> catalyst of issues like this.
>
> In any case, is there a breakdown on what OSSEC's limitation/capacity
> is in respect to this? Of course, I'm sure it's partly dependent on
> hardware capacity. One of the servers, in the same load-balanced vip,
> did not experience these symptoms. The difference is that this
> particular server is running on leveled-up hardware (DL380 G4 versus
> the ones with issues: DL360 G4's) and and a newer OS. I believe the
> DL360 G4's are both running 2.6.12-1.1372_FC3smp (Fedora Core 3?!?!?!)
> while the DL380 G4 is on RH (not sure which version but if I had to
> guess a more recent version of RHEL).
>
> Besides the 'obvious' rhetoric: "upgrade your hardware and software!"
> - is there any other possible avenues to investigate with why the
> ossec-agentd was unable to handle the volume of log growth? Obviously
> it's the rate at which events are generated in the logs as we
> understand that OSSEC does not read in the entire file at once, etc
>
> Any ideas or suggestions?
>
>
> TIA!
>
>

Reply via email to