Running antivirus in Linux with a Stream worker?
Hello all, some customer is asking to have an antivirus (!!?!?!?) on the Linux server running a Cribl Stream worker. I found some recommendations for Edge in the documentation, but nothing for Stream. Is it supported, for Stream, having such a configuration? thanks a lot
Answers
-
Thanks David. So this is applicable also for a distributed deployment.
0 -
Yes
0 -
<#C01BM8PU30V|docs> <@U03CJ90F91A> perhaps we should also add this info to our distributed deployment pages too.
0 -
thanks again. Do you have some performance numbers, how much degraded is the cribl system using this configuration?
0 -
That is likely depending a LOT on the actual AV used and it's config
0 -
Yes, it makes sense
0 -
From working endpoint security before, I can tell you that they need antivirus on all the things all the time or auditors get upset
0 -
Lack of AV on a linux server can be mitigated by a subset of selinux, file integrity tests, root kit detectors, good monitoring, and especially auditable config. Flies with our auditors.
0 -
The ability to destroy and rebuild a node in minutes doesn't hurt either.
0 -
yes, selinux can be a good idea, but no one on the customer side is able to manage that.
0 -
Oh, that does complicate matters. /condolences
0