Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 519 forks source link

sosetup: new production deployments should default to LOGSTASH_MINIMAL #1732

Closed dougburks closed 4 years ago

dougburks commented 4 years ago

We are going to start defaulting new production deployments to LOGSTASH_MINIMAL, so that Logstash will no longer parse logs itself and only transport them to Elasticsearch where they are parsed using ingest node. This should result in Logstash initializing faster and better overall performance.

It should be noted that we will only be setting LOGSTASH_MINIMAL and NOT changing the default heap size (unlike sosetup-minimal which sets LOGSTASH_MINIMAL and also decreases heap size).

dougburks commented 4 years ago

The following package is now available at ppa:securityonion/test:

securityonion-setup - 20120912-0ubuntu0securityonion326

Please test/verify as follows:

Thanks in advance for your time and testing!

dougburks commented 4 years ago

Published: https://blog.securityonion.net/2020/03/security-onion-160465-iso-image-now.html