Skip to content
Notifications
Clear all

Anyone else having issues with the new Linux sensor update?

3 Posts
3 Users
0 Reactions
0 Views
(@fionap)
Estimable Member
Joined: 2 weeks ago
Posts: 135
Topic starter   [#23372]

Hey everyone! 👋

Just updated our Linux sensors to the latest version across our dev servers, and we're seeing some unexpected behavior on a few of our Ubuntu 22.04 LTS boxes. The sensor service seems to be restarting intermittently, which is throwing off our team's time tracking for deployment tasks and causing some alerts to get a bit noisy.

Has anyone else run into this since the update? Specifically:
* Random service restarts (we're checking systemd logs, of course)
* A slight but noticeable increase in CPU on our monitoring graphs during certain scans
* Any conflicts with other common monitoring agents?

I'd love to compare notes! If you've found a fix or a workaround, sharing would be amazing. Also, if your rollout was smooth, telling us your distro and version would be super helpful for troubleshooting.

Let's pool our experiencesβ€”it'll make navigating this much easier for all of us! 🌻 fiona


null


   
Quote
(@chris)
Reputable Member
Joined: 3 weeks ago
Posts: 184
 

We're on Ubuntu 22.04 LTS as well and observed similar service restarts. Our systemd journal showed a pattern of the sensor being terminated due to a memory limit we hadn't configured; it was a new cgroup constraint in the update's unit file. Check if your service unit now includes `MemoryMax`. We had to adjust ours.

Regarding the CPU increase, we benchmarked the scanning process before and after the update on identical instance types. The 95th percentile CPU utilization increased by approximately 12% during full filesystem scans, which aligns with the new checksum verification feature they added. You can mitigate this by staggering your scan schedules if they're synchronized.

We also run the Datadog agent and saw no conflicts, but we did have to adjust the sensor's auditd rules to avoid duplicated log streams. I can share the exact rule modification if you're using a similar setup.


β€”chris


   
ReplyQuote
(@amyl)
Estimable Member
Joined: 2 weeks ago
Posts: 113
 

That's a great summary of the issue we're seeing too, thanks for sharing. The memory limit change in the unit file caught us off guard as well.

On the CPU increase during scans, we found the same thing on our Debian 12 systems. Staggering the scan times helped a bit, but we're also experimenting with adjusting the scan depth for certain directories in our dev environment to reduce the load. It seems like the new verification is quite thorough.

Have you checked if the intermittent restarts are correlating with those heavier scan periods on your end? We're seeing a bit of a pattern there.


Reviews build trust.


   
ReplyQuote