Here is a thread on some performance tests that I ran on OSSEC http://groups.google.com/group/ossec-list/browse_thread/thread/224408b3f6b034a8/f758743dacf7ed72?lnk=gst&q=performance+testing#f758743dacf7ed72
<http://groups.google.com/group/ossec-list/browse_thread/thread/224408b3f6b034a8/f758743dacf7ed72?lnk=gst&q=performance+testing#f758743dacf7ed72>I found that ossec took approx 65%-70% CPU at 11,000 EPS. The test setup max'd out at 14000 EPS. I was testing on a 2 CPU, 4 GB RAM VM (which is not even as good as a Core Duo Intel desktop CPU) On Sat, Jan 8, 2011 at 12:37 PM, jplee3 <[email protected]> wrote: > Hi all, > > We experienced 90%+ utliziation from the ossec-agentd on a couple > servers this morning and I was able to trace it to a log file that > grew extremely large in a relatively short time window (1gb of growth > within a 2-3 hour time window). After removing the log for OSSEC to > monitor, agentd quieted down. Prior to this the systems were almost to > the point of being hosed. This is on Linux btw. I read an article > mentioning excessive # of events at least in Windows will be the > catalyst of issues like this. > > In any case, is there a breakdown on what OSSEC's limitation/capacity > is in respect to this? Of course, I'm sure it's partly dependent on > hardware capacity. One of the servers, in the same load-balanced vip, > did not experience these symptoms. The difference is that this > particular server is running on leveled-up hardware (DL380 G4 versus > the ones with issues: DL360 G4's) and and a newer OS. I believe the > DL360 G4's are both running 2.6.12-1.1372_FC3smp (Fedora Core 3?!?!?!) > while the DL380 G4 is on RH (not sure which version but if I had to > guess a more recent version of RHEL). > > Besides the 'obvious' rhetoric: "upgrade your hardware and software!" > - is there any other possible avenues to investigate with why the > ossec-agentd was unable to handle the volume of log growth? Obviously > it's the rate at which events are generated in the logs as we > understand that OSSEC does not read in the entire file at once, etc > > Any ideas or suggestions? > > > TIA! > >
