Skip to content

so-elasticsearch container crashes/exits #4198

Locked Answered by dougburks
netsecninja asked this question in General
Discussion options

You must be logged in to vote

The most likely reason for Elasticsearch exiting randomly like that is due to heap or memory issues. The heap is set solely based on your RAM with no knowledge of how much heap is actually necessary for the ingestion rate. So if this is a production deployment monitoring a busy network, it's quite possible that you may need more RAM in the box and/or more heap for Elasticsearch. Please note that 16GB RAM is the bare minimum for a production deployment:
https://docs.securityonion.net/en/2.3/hardware.html#standalone-deployments

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@netsecninja
Comment options

Answer selected by netsecninja
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants