google / grr

GRR Rapid Response: remote live forensics for incident response

Home Page:https://grr-doc.readthedocs.io/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

GRR_Server log size increases very fast

makitos666 opened this issue · comments

Environment

  • How did you install GRR?
    From DEB
  • What GRR version are you running?:
    3.4.2.4
  • What operating system does the GRR server run on?
    Ubuntu 20.04
  • What operating system does the affected GRR client run on, if applicable?
    N/A

Describe the issue
These two logs are growing at an incredible speed:

  • /var/log/syslog
  • /usr/share/grr-server/lib/python3.6/site-packages/grr_response_core/var/log/grr-worker.log

In a few hours more than 40GB are generated.
Is it possible to adjust the verbosity? Is it necessary for the same error (such as access to the DB) to generate an error log every millisecond?

@makitos666 - can you please post a sample of the message that is repeated every millisecond?

Is it possible to adjust the verbosity? Is it necessary for the same error (such as access to the DB) to generate an error log every millisecond?

There are ways to configure verbosity, but default verbosity settings normally don't generate too much noise. Also, not being to access the database is a fatal error for the worker - the worker won't function if this is not fixed. Can you please check if the worker is actually working?