wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
9.72k stars 1.53k forks source link

Release 4.6.0 - Alpha 1 - Footprint Metrics - ROOTCHECK (2.5d) #18925

Closed wazuhci closed 10 months ago

wazuhci commented 10 months ago

Footprint metrics information

Main release candidate issue # #18858
Main footprint metrics issue # #18862
Version 4.6.0
Release candidate # RC1
Tag https://github.com/wazuh/wazuh/tree/4.6.0-rc1

Stress test documentation

Packages used


Manager +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_FD.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_PSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_SWAP.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/monitor-manager-Test_stress_B4292_manager-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/Test_stress_B4292_manager_analysisd_events_Decoded_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/Test_stress_B4292_manager_analysisd_events_Dropped_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/Test_stress_B4292_manager_analysisd_events_EDPS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/Test_stress_B4292_manager_analysisd_events_Written_stats.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/Test_stress_B4292_manager_analysisd_state_Number_Events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/plots/Test_stress_B4292_manager_analysisd_state_Queues_state.png)
  • Logs and configuration [ossec_Test_stress_B4292_manager_2023-09-10.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/logs/ossec_Test_stress_B4292_manager_2023-09-10.zip)
  • CSV [monitor-manager-Test_stress_B4292_manager-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/data/monitor-manager-Test_stress_B4292_manager-pre-release.csv) [Test_stress_B4292_manager_analysisd_events.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/data/Test_stress_B4292_manager_analysisd_events.csv) [Test_stress_B4292_manager_analysisd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/data/Test_stress_B4292_manager_analysisd_state.csv) [Test_stress_B4292_manager_remoted_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_manager_centos/data/Test_stress_B4292_manager_remoted_state.csv)

Centos agent +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_FD.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_PSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_SWAP.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/monitor-agent-Test_stress_B4292_centos-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/Test_stress_B4292_centos_agentd_state_AgentD_Number_of_events_buffered.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/Test_stress_B4292_centos_agentd_state_AgentD_Number_of_generated_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/Test_stress_B4292_centos_agentd_state_AgentD_Number_of_messages.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/plots/Test_stress_B4292_centos_agentd_state_AgentD_Status.png)
  • Logs and configuration [ossec_Test_stress_B4292_centos_2023-09-10.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/logs/ossec_Test_stress_B4292_centos_2023-09-10.zip)
  • CSV [monitor-agent-Test_stress_B4292_centos-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/data/monitor-agent-Test_stress_B4292_centos-pre-release.csv) [Test_stress_B4292_centos_agentd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_centos/data/Test_stress_B4292_centos_agentd_state.csv)

Ubuntu agent +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_FD.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_PSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_SWAP.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/monitor-agent-Test_stress_B4292_ubuntu-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/Test_stress_B4292_ubuntu_agentd_state_AgentD_Number_of_events_buffered.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/Test_stress_B4292_ubuntu_agentd_state_AgentD_Number_of_generated_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/Test_stress_B4292_ubuntu_agentd_state_AgentD_Number_of_messages.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/plots/Test_stress_B4292_ubuntu_agentd_state_AgentD_Status.png)
  • Logs and configuration [ossec_Test_stress_B4292_ubuntu_2023-09-10.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/logs/ossec_Test_stress_B4292_ubuntu_2023-09-10.zip)
  • CSV [monitor-agent-Test_stress_B4292_ubuntu-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/data/monitor-agent-Test_stress_B4292_ubuntu-pre-release.csv) [Test_stress_B4292_ubuntu_agentd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_ubuntu/data/Test_stress_B4292_ubuntu_agentd_state.csv)

Windows agent +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_Handles.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/monitor-winagent-Test_stress_B4292_windows-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/Test_stress_B4292_windows_agentd_state_AgentD_Number_of_events_buffered.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/Test_stress_B4292_windows_agentd_state_AgentD_Number_of_generated_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/Test_stress_B4292_windows_agentd_state_AgentD_Number_of_messages.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/plots/Test_stress_B4292_windows_agentd_state_AgentD_Status.png)
  • Logs and configuration [ossec_Test_stress_B4292_windows_2023-09-10.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/logs/ossec_Test_stress_B4292_windows_2023-09-10.zip)
  • CSV [monitor-winagent-Test_stress_B4292_windows-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/data/monitor-winagent-Test_stress_B4292_windows-pre-release.csv) [Test_stress_B4292_windows_agentd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.6.0/B4292-3600m/B4292_agent_windows/data/Test_stress_B4292_windows_agentd_state.csv)

Conclusion :red_circle:

During testing no anomalies were found on the graphs, but the following Issues have been detected:

Deblintrake09 commented 10 months ago

Analysis report: Logs

Manager ```json { "ossec-07.log": { "WARNING": { "wazuh-modulesd WARNING: Ubuntu Precise is no longer supported.": { "count": 12 }, "wazuh-logcollector WARNING: Target 'agent' message queue is full (1024). Log lines may be lost.": { "count": 1 } } }, "ossec-09.log": { "WARNING": { "wazuh-remoted WARNING: Too big message size from socket [23].": { "count": 2 } } }, "ossec-08.log": { "WARNING": { "wazuh-remoted WARNING: Too big message size from socket [21].": { "count": 12 } } } } ``` - Known Issues: - https://github.com/wazuh/wazuh/issues/17596 - https://github.com/wazuh/wazuh-jenkins/issues/5628
Centos ```json { "ossec-07.log": { "ERROR": { "wazuh-agentd ERROR: (1137): Lost connection with manager. Setting lock.": { "count": 1 }, "wazuh-agentd ERROR: (1216): Unable to connect to '[172.31.13.238]:1514/tcp': 'Connection refused'.": { "count": 2 } } } } ``` - Known Issue: https://github.com/wazuh/wazuh-jenkins/issues/4867
Ubuntu ```json { "ossec-07.log": { "ERROR": { "wazuh-agentd ERROR: (1216): Unable to connect to '[172.31.13.238]:1514/tcp': 'Connection refused'.": { "count": 1 } } } } ``` - Known Issue: https://github.com/wazuh/wazuh-jenkins/issues/4867
Windows ```json { "logs\\2023\\Sep\\ossec-07.log": { "ERROR": { "wazuh-agent ERROR: (1208): Unable to connect to enrollment service at '[172.31.13.238]:1515'": { "count": 1 } }, "WARNING": { "wazuh-agent WARNING: The file 'C:\\Program Files (x86)\\ossec-agent\\libfimdb.dll' is not signed or its signature is invalid.": { "count": 2 } } } } ``` - Reported in https://github.com/wazuh/wazuh/issues/18952

Analysis report: Graphs

No abnormal behavior found in comparison with stage 4.5.2 RC 1

juliamagan commented 10 months ago

Please add all reported issues to the main issue comment, separating the new ones from the known ones.

Also, if a new issue has been reported, the conclusion cannot be :green_circle:, it should be :red_circle: if there are any new issues and :yellow_circle: if all issues are known.

juliamagan commented 10 months ago

LGTM

damarisg commented 10 months ago

LGTM!