wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
10.92k stars 1.66k forks source link

Release 4.9.0 - RC 2 - Footprint Metrics - VULNERABILITY-DETECTOR-REGISTER (2.5d) #25530

Closed wazuhci closed 2 months ago

wazuhci commented 2 months ago

Footprint metrics information

Main release stage issue # #25475
Main footprint metrics issue # #25488
Version 4.9.0
Release stage # RC 2
Tag https://github.com/wazuh/wazuh/tree/v4.9.0-rc2

Stress test documentation

Packages used


Manager +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_FD.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_PSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_SWAP.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/monitor-manager-Test_stress_B5571_manager-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/Test_stress_B5571_manager_analysisd_events_Decoded_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/Test_stress_B5571_manager_analysisd_events_Dropped_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/Test_stress_B5571_manager_analysisd_events_EDPS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/Test_stress_B5571_manager_analysisd_events_Written_stats.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/Test_stress_B5571_manager_analysisd_state_Number_Events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/plots/Test_stress_B5571_manager_analysisd_state_Queues_state.png)
  • Logs and configuration [ossec_Test_stress_B5571_manager_2024-09-02.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/logs/ossec_Test_stress_B5571_manager_2024-09-02.zip)
  • CSV [monitor-manager-Test_stress_B5571_manager-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/data/monitor-manager-Test_stress_B5571_manager-pre-release.csv) [Test_stress_B5571_manager_analysisd_events.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/data/Test_stress_B5571_manager_analysisd_events.csv) [Test_stress_B5571_manager_analysisd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/data/Test_stress_B5571_manager_analysisd_state.csv) [Test_stress_B5571_manager_remoted_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_manager_centos/data/Test_stress_B5571_manager_remoted_state.csv)

Centos agent +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_FD.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_PSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_SWAP.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/monitor-agent-Test_stress_B5571_centos-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/Test_stress_B5571_centos_agentd_state_AgentD_Number_of_events_buffered.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/Test_stress_B5571_centos_agentd_state_AgentD_Number_of_generated_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/Test_stress_B5571_centos_agentd_state_AgentD_Number_of_messages.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/plots/Test_stress_B5571_centos_agentd_state_AgentD_Status.png)
  • Logs and configuration [ossec_Test_stress_B5571_centos_2024-09-02.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/logs/ossec_Test_stress_B5571_centos_2024-09-02.zip)
  • CSV [monitor-agent-Test_stress_B5571_centos-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/data/monitor-agent-Test_stress_B5571_centos-pre-release.csv) [Test_stress_B5571_centos_agentd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_centos/data/Test_stress_B5571_centos_agentd_state.csv)

Ubuntu agent +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_FD.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_PSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_SWAP.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/monitor-agent-Test_stress_B5571_ubuntu-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/Test_stress_B5571_ubuntu_agentd_state_AgentD_Number_of_events_buffered.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/Test_stress_B5571_ubuntu_agentd_state_AgentD_Number_of_generated_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/Test_stress_B5571_ubuntu_agentd_state_AgentD_Number_of_messages.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/plots/Test_stress_B5571_ubuntu_agentd_state_AgentD_Status.png)
  • Logs and configuration [ossec_Test_stress_B5571_ubuntu_2024-09-02.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/logs/ossec_Test_stress_B5571_ubuntu_2024-09-02.zip)
  • CSV [monitor-agent-Test_stress_B5571_ubuntu-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/data/monitor-agent-Test_stress_B5571_ubuntu-pre-release.csv) [Test_stress_B5571_ubuntu_agentd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_ubuntu/data/Test_stress_B5571_ubuntu_agentd_state.csv)

Windows agent +
Plots ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_CPU.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_Disk.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_Disk_Read.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_Disk_Written.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_Handles.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_Read_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_RSS_MAXMIN.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_RSS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_USS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_VMS.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/monitor-winagent-Test_stress_B5571_windows-pre-release_Write_Ops.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/Test_stress_B5571_windows_agentd_state_AgentD_Number_of_events_buffered.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/Test_stress_B5571_windows_agentd_state_AgentD_Number_of_generated_events.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/Test_stress_B5571_windows_agentd_state_AgentD_Number_of_messages.png) ![](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/plots/Test_stress_B5571_windows_agentd_state_AgentD_Status.png)
  • Logs and configuration [ossec_Test_stress_B5571_windows_2024-09-02.zip](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/logs/ossec_Test_stress_B5571_windows_2024-09-02.zip)
  • CSV [monitor-winagent-Test_stress_B5571_windows-pre-release.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/data/monitor-winagent-Test_stress_B5571_windows-pre-release.csv) [Test_stress_B5571_windows_agentd_state.csv](https://ci.wazuh.com/data/Test_stress/pre-release/4.9.0/B5571-3600m/B5571_agent_windows/data/Test_stress_B5571_windows_agentd_state.csv)

macOS agent +
Plots
  • Logs and configuration
  • CSV

Solaris agent +
Plots
  • Logs and configuration
  • CSV

Conclusion :yellow_circle:

Plots :yellow_circle:

Known issues:

Logs :yellow_circle:

Known issues:

pro-akim commented 2 months ago

Analysis report

Graphs :yellow_circle:

Compared to: https://github.com/wazuh/wazuh/issues/24471

Ubuntu

No abnormalities were found

Manager

CPU: Absence of modulesd peaks at the start of the test Disk: relevant decrease of modulesd, now follows the pattern of wazuhdb and wazuh-authd Disk_Read: Large drop in modules with a more staggered ascending pattern until reaching a valley Disk_Written: relevant decrease of modulesd, now follows the pattern of wazuhdb and wazuh-authd FD: decrease of modulesd PSS, RSS y USS : decrease of modulesd VMS: decrease of modulesd Dropped_events: Increase of events Read_Ops: decrease of modulesd

This changes were reported in 4.9.0-Beta2 and they were considered performance improvement

Centos

No abnormalities were found

Windows

All plots are shown altered with respect to 4.8.1-RC2 but present patterns and values similar to 4.9.0-Beta1, 4.9.0-Beta2, and 4.9.0-RC1

Logs :yellow_circle:

Ubuntu ``` 2024/08/31 01:56:47 wazuh-agentd ERROR: (1216): Unable to connect to '[172.31.4.94]:1514/tcp': 'Connection refused'. 2024/08/31 01:57:07 wazuh-agentd WARNING: Agent buffer is full: Events may be lost. ```
Manager - Reported: https://github.com/wazuh/wazuh/issues/22565 - Known issue ``` 2024/08/31 01:53:55 indexer-connector WARNING: No username and password found in the keystore, using default values. 2024/08/31 01:53:55 indexer-connector WARNING: IndexerConnector initialization failed for index 'wazuh-states-vulnerabilities-ip-172-31-4-94.ec2.internal', retrying until the connection is successful. 2024/08/31 01:56:21 indexer-connector WARNING: Failed to sync agent '001' with the indexer. ``` - Expected in stress test ``` 2024/08/31 01:56:02 wazuh-logcollector WARNING: Target 'agent' message queue is full (1024). Log lines may be lost. 2024/08/31 17:06:38 wazuh-remoted WARNING: Message queue is full (10). Events may be lost. ``` - Reported: https://github.com/wazuh/wazuh-jenkins/issues/6368 - Known issue ``` 2024/08/31 01:56:54 wazuh-modulesd:vulnerability-scanner WARNING: The 'feed-update-interval' option at module 'vulnerability-detection' must be at least 1 hour. Automatically set to 60 minutes. ```
Centos - Reported: https://github.com/wazuh/wazuh-jenkins/issues/4867 - Known issue ``` 2024/08/31 01:56:40 wazuh-agentd ERROR: (1137): Lost connection with manager. Setting lock. 2024/08/31 01:56:40 wazuh-agentd ERROR: (1216): Unable to connect to '[172.31.4.94]:1514/tcp': 'Connection refused'. 2024/08/31 01:56:21 wazuh-agentd WARNING: Agent buffer is full: Events may be lost. ```
Windows - Reported: https://github.com/wazuh/wazuh-jenkins/issues/4867 - Known issue ``` 2024/08/31 01:56:39 wazuh-agent ERROR: (1137): Lost connection with manager. Setting lock. 2024/08/31 01:56:40 wazuh-agent ERROR: (1216): Unable to connect to '[172.31.4.94]:1514/tcp': 'No connection could be made because the target machine actively refused it.'. ``` - Expected in stress test ``` 2024/08/31 01:56:36 wazuh-agent WARNING: Agent buffer at 90 %. 2024/08/31 02:56:41 wazuh-agent WARNING: Agent buffer is full: Events may be lost. ```
MARCOSD4 commented 2 months ago

LGTM