Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 519 forks source link

Zeek 3.0.3 #1726

Closed dougburks closed 4 years ago

dougburks commented 4 years ago

https://github.com/zeek/zeek/releases/tag/v3.0.2

dougburks commented 4 years ago

Zeek 3.0.2 has a performance issue which is scheduled to be resolved in 3.0.3:

https://groups.google.com/d/topic/security-onion/LvXkYcQlh3Y/discussion

http://mailman.icsi.berkeley.edu/pipermail/zeek/2020-March/015153.html

dougburks commented 4 years ago

https://github.com/zeek/zeek/releases/tag/v3.0.3

dougburks commented 4 years ago

List of packages to be tested:

Other issues to be tested: https://github.com/Security-Onion-Solutions/security-onion/issues/1727

An overview of the testing process can be found in the comments below.

Please record all testing results via comments on this issue.

Thanks in advance for your time effort!

dougburks commented 4 years ago

How To Start Testing

Please note that we also have Elastic packages and Docker images in testing right now, so if you want to test just this Zeek update, you should be able to replace that last command with:

sudo apt update && sudo apt install securityonion-bro securityonion-bro-afpacket securityonion-bro-scripts securityonion-samples-bro
dougburks commented 4 years ago

How To Verify Proper Zeek Operation

Please test in as many different combinations as possible:

petiepooo commented 4 years ago

Soaking on one system to verify no cpu load spiking... I'll try to get through some of the other test situations asap..

Thanks for turning this around so quickly, Doug!

dougburks commented 4 years ago

Thanks @petiepooo , I really appreciate you bringing this issue to light and helping us turn it around quickly!

petiepooo commented 4 years ago

Soaked on one system for nearly two days and another busier system for over 12 hours.. I would have normally seen at least one worker jump to 100% CPU by now, I believe, so I'm convinced this does fix the CPU load issue.

This is just using af_packet and 2 or 4 workers with the package run in as an upgrade. No regressions noted WRT extracts, elastic ingestion, ja3, hassh, etc. I haven't yet installed via ISO or tried eval mode, pf_ring, multiple ifaces, CSV logs, vlans, etc.

dougburks commented 4 years ago

Thanks again for your time and testing @petiepooo !

petiepooo commented 4 years ago

Soaked on 6 systems over the weekend with no ill effects and no spike in CPU usage. Still no regressions noted, but still limited to just upgrading existing deployments.

weslambert commented 4 years ago

No issues with Zeek from my testing 👍 .

dougburks commented 4 years ago

Published: https://blog.securityonion.net/2020/03/zeek-303-now-available-for-security.html