wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
9.66k stars 1.53k forks source link

Increase `analysisd` fluctuations on footprint metrics for 4.8.0 Beta 2 #22222

Closed QU3B1M closed 4 months ago

QU3B1M commented 4 months ago
Wazuh version Component Install type Install method Platform
4.8.0-beta2 Wazuh Manager Manager Packages CentOS

Description

During the analysis Release 4.8.0 - Beta 2 - Footprint Metrics - ACTIVE-RESPONSE (2.5d) detected an increase of the analysisd fluctuations and the usage decreased, compared to 4.7.2

cborla commented 4 months ago

Analysis

Configuration

ossec.conf

image

internal_options.conf and local_internal_options.conf

Test

test_active_response.log

The active response test was triggered almost the same amount of times for the 2 versions, only a difference of 0.5 % more in 4.8.0.

Data analysis

The following table shows the differences in memory usage between the two versions, as well as the difference in disk usage.

image