I have a sensor with a i5-4590, 8GB memory running packetbeat and am still getting "dropped_because_of_gaps"
I've followed all the directions about enabling af_packet, etc yet even on a low traffic link (1-5mbps) I still get dropped events - what else can I do?
Do you know if you had tried to comment that one out? It should commonly resolve the issue.
However, if it does not work, and you are still seeing issues, could you try to set this one to false, and just see if it helps, at least then we are able to narrow it down a bit more:
So the above configuration, is af_packet currently enable, and no other fields are different from the configuration you linked?
The reason I wanted to disable it, was not to provide it as a solution, but to try to find out what might cause your issue.
Would you be able to share a logfile for example? It might include sensitive information, so if its not from a test environment of some sort, I was just wondering where you found your metrics and if you could grep the logfiles for any "ERROR" or "WARN" as well after restarting it and letting it run for a couple of minutes.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.