Page 1 of 1

OSSEC usign too much bandwidth

Posted: Wed Feb 24, 2021 1:33 pm
by lelylo
Hello Eveyone:

I have a problem with our OSEC agents right now. We use OSSEC to monitor events and send them to our SIEM AlienVault.
The problem we have is that in the last week, it has been usign too much bandwidht in our network.
Cheking the SIEM server I found too many packets beeing send by port 1514 with the same lenght, 417. ( some little cases 409)

I have never seen this behaviour before.
I have checked the audit configuration inside my WIndows workstations (where is OSSEC installed), and the the adit is enable just for security logs.
Please let me know if you have some idea of this behaviour.
Thanks!!

Re: OSSEC usign too much bandwidth

Posted: Thu Feb 25, 2021 11:35 am
by cponton
I am sorry to hear that! We do have some checks you can do when there is high load issues. Please take a look here and see if any of these steps help:
https://support.atomicorp.com/hc/en-us/ ... h-CPU-load

Re: OSSEC usign too much bandwidth

Posted: Wed Mar 03, 2021 4:12 pm
by mikeshinn
What version of OSSEC are using?