PCAP Files keep filling up Hard Drive #673
Unanswered
DJNAT10
asked this question in
Troubleshooting
Replies: 1 comment
-
Sure, here are a few things we can check:
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Good Morning,
I'm reaching out to you to help with an issue we're having related to Malcolm. We are currently rebuilding due to a hardware failure. Specifically, we've encountered a critical issues:
• The system hard drive becoming full over the weekend, in addition the server stopped working and we weren't able to restart. Restart did work however when we deleted the PCAP files.
Here are the relevant environment configurations we've set:
• MANAGE_PCAP_FILES=true
• ARKIME_FREESPACEG=75%
according to the documentation, Arkime should begin deleting the oldest pcap files once disk space drops below 75% free, but this does not appear to be occurring.
Additionally, for index management:
• We have configured OPENSEARCH_INDEX_SIZE_PRUNE_LIMIT=60% in dashboards-helper.env to manage OpenSearch indices, with a limit to prune older indices as needed.
We have a single data partition /Malcolmdata both PCAP and OpenSearch data are writing to this shared 10 Terabyte partition.
Despite these settings, the disk usage continues to grow until it was completely full, and Arkime stopped showing data. We would appreciate your help identifying the problem so we can find the solution.
Please let us know how we can proceed to further troubleshoot or provide more context.
Best regards,
Natasha Jones
Beta Was this translation helpful? Give feedback.
All reactions