<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[1100 upgrade, 22.05-&gt;23.01, high mem usage]]></title><description><![CDATA[<p dir="auto">I upgraded yesterday afternoon, no problems there.  Now I notice my memory usage is high.  "top -o size" shows that unbound is using 175M.  Here is a graph of memory usage over the last two days.  The change in version is kind of obvious there.  I'm worried that unbound has a mem leak or will kill my system.  Advice please?</p>
<p dir="auto"><img src="/assets/uploads/files/1676727342930-screenshot-2023-02-18-at-8.31.10-am.png" alt="Screenshot 2023-02-18 at 8.31.10 AM.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/178023/1100-upgrade-22-05-23-01-high-mem-usage</link><generator>RSS for Node</generator><lastBuildDate>Fri, 14 Aug 2026 15:34:11 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/178023.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 18 Feb 2023 13:37:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sun, 26 Feb 2023 20:09:31 GMT]]></title><description><![CDATA[<p dir="auto">@mr-castoro -- No problems with my SG-1100 and DNS but I use the "Forwarder" and not the "Resolver" and I point the Forwarder to my two Pi-hole IPs.  Works great that way!</p>
<p dir="auto">Also, instead of pointing it to a Pi-hole, you could just use: 9.9.9.9, 1.1.1.1 or 8.8.8.8 or some other external DNS.</p>
]]></description><link>https://forum.netgate.com/post/1090668</link><guid isPermaLink="true">https://forum.netgate.com/post/1090668</guid><dc:creator><![CDATA[rpsmith]]></dc:creator><pubDate>Sun, 26 Feb 2023 20:09:31 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sun, 26 Feb 2023 16:54:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/machasachaira">@<bdi>machasachaira</bdi></a> yes, several times</p>
]]></description><link>https://forum.netgate.com/post/1090620</link><guid isPermaLink="true">https://forum.netgate.com/post/1090620</guid><dc:creator><![CDATA[mr.castoro]]></dc:creator><pubDate>Sun, 26 Feb 2023 16:54:43 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sun, 26 Feb 2023 14:47:02 GMT]]></title><description><![CDATA[<p dir="auto">@mr-castoro Have you restarted your SG after the patch update? I have not experienced any problems after rebooting.</p>
]]></description><link>https://forum.netgate.com/post/1090579</link><guid isPermaLink="true">https://forum.netgate.com/post/1090579</guid><dc:creator><![CDATA[MachasaChaira]]></dc:creator><pubDate>Sun, 26 Feb 2023 14:47:02 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sun, 26 Feb 2023 13:49:51 GMT]]></title><description><![CDATA[<p dir="auto">@mr-castoro There are a bunch of DNS threads lately.<br />
If you have Resolver set to forward, ensure DNSSEC is unchecked.</p>
]]></description><link>https://forum.netgate.com/post/1090563</link><guid isPermaLink="true">https://forum.netgate.com/post/1090563</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sun, 26 Feb 2023 13:49:51 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sun, 26 Feb 2023 13:15:08 GMT]]></title><description><![CDATA[<p dir="auto">Applied this patch 2 days ago.  Absolutely solved the 3am memory leak.  However, dns broke on my sg 1100 the past two days.  I had to restart the dns resolver service to restore dns.   Anyone else experiencing this?</p>
]]></description><link>https://forum.netgate.com/post/1090553</link><guid isPermaLink="true">https://forum.netgate.com/post/1090553</guid><dc:creator><![CDATA[mr.castoro]]></dc:creator><pubDate>Sun, 26 Feb 2023 13:15:08 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sat, 25 Feb 2023 18:01:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a>  Thanks</p>
]]></description><link>https://forum.netgate.com/post/1090345</link><guid isPermaLink="true">https://forum.netgate.com/post/1090345</guid><dc:creator><![CDATA[JMV43 0]]></dc:creator><pubDate>Sat, 25 Feb 2023 18:01:34 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sat, 25 Feb 2023 15:59:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/machasachaira">@<bdi>machasachaira</bdi></a> :) System Patches is relatively new (1-2 years), and a wonderful idea.  Netgate publishes a list of Recommended patches for the version you're on.  Updating that package updates the list of patches.  Any patch with a commit ID can also be pulled in.</p>
]]></description><link>https://forum.netgate.com/post/1090296</link><guid isPermaLink="true">https://forum.netgate.com/post/1090296</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sat, 25 Feb 2023 15:59:16 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sat, 25 Feb 2023 15:35:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a> I didn't know that way, I used the fetch command on the CLI to bring the file and replace the original.</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/post/1090284</link><guid isPermaLink="true">https://forum.netgate.com/post/1090284</guid><dc:creator><![CDATA[MachasaChaira]]></dc:creator><pubDate>Sat, 25 Feb 2023 15:35:50 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sat, 25 Feb 2023 15:58:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jmv43-0">@<bdi>jmv43-0</bdi></a> Install the System Patches package and use the patch ID.<br />
<a href="https://docs.netgate.com/pfsense/en/latest/development/system-patches.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/development/system-patches.html</a></p>
]]></description><link>https://forum.netgate.com/post/1090269</link><guid isPermaLink="true">https://forum.netgate.com/post/1090269</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sat, 25 Feb 2023 15:58:41 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Sat, 25 Feb 2023 15:03:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/machasachaira">@<bdi>machasachaira</bdi></a> How do we apply the patch?</p>
<p dir="auto">JMV</p>
]]></description><link>https://forum.netgate.com/post/1090263</link><guid isPermaLink="true">https://forum.netgate.com/post/1090263</guid><dc:creator><![CDATA[JMV43 0]]></dc:creator><pubDate>Sat, 25 Feb 2023 15:03:22 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Fri, 24 Feb 2023 11:35:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fsc830">@<bdi>fsc830</bdi></a> Applied this patch in my SG-3100, everything OK, memory usage didn't change at night.<br />
Thanks</p>
]]></description><link>https://forum.netgate.com/post/1089938</link><guid isPermaLink="true">https://forum.netgate.com/post/1089938</guid><dc:creator><![CDATA[mcury]]></dc:creator><pubDate>Fri, 24 Feb 2023 11:35:42 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Fri, 24 Feb 2023 07:36:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rpsmith">@<bdi>rpsmith</bdi></a> said in <a href="/post/1089722">1100 upgrade, 22.05-&gt;23.01, high mem usage</a>:</p>
<blockquote>
<p dir="auto">Patch "ff715efce5e6c65b3d49dc2da7e1bdc437ecbf12" has completely resolved my SG-1100 memory problems!</p>
</blockquote>
<p dir="auto">+1<br />
<img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /><br />
Applied patch and rebootet yesterday at 8:00pm</p>
<p dir="auto"><img src="/assets/uploads/files/1677224179992-f6556b8f-56be-4a04-bd61-5ca50ebae3ee-grafik.png" alt="f6556b8f-56be-4a04-bd61-5ca50ebae3ee-grafik.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Regards</p>
]]></description><link>https://forum.netgate.com/post/1089897</link><guid isPermaLink="true">https://forum.netgate.com/post/1089897</guid><dc:creator><![CDATA[FSC830]]></dc:creator><pubDate>Fri, 24 Feb 2023 07:36:37 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Thu, 23 Feb 2023 19:01:50 GMT]]></title><description><![CDATA[<p dir="auto">Patch "ff715efce5e6c65b3d49dc2da7e1bdc437ecbf12" has completely resolved my SG-1100 memory problems!</p>
]]></description><link>https://forum.netgate.com/post/1089722</link><guid isPermaLink="true">https://forum.netgate.com/post/1089722</guid><dc:creator><![CDATA[rpsmith]]></dc:creator><pubDate>Thu, 23 Feb 2023 19:01:50 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Thu, 23 Feb 2023 12:57:10 GMT]]></title><description><![CDATA[<p dir="auto">Checking my system this morning after applying patch ff715efce5e6c65b3d49dc2da7e1bdc437ecbf12 and rebooting yesterday...  Bliss!  Nothing happened at 3 AM and my wired mem usage remains at about 35%.  I consider this problem solved.</p>
<p dir="auto"><img src="/assets/uploads/files/1677156987654-screenshot-2023-02-23-at-7.49.39-am.png" alt="Screenshot 2023-02-23 at 7.49.39 AM.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1089609</link><guid isPermaLink="true">https://forum.netgate.com/post/1089609</guid><dc:creator><![CDATA[beerguzzle]]></dc:creator><pubDate>Thu, 23 Feb 2023 12:57:10 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Thu, 23 Feb 2023 00:14:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beerguzzle">@<bdi>beerguzzle</bdi></a> Hello, my first comment here. Same situation, SG-1100 with 85% memory in constant use. I applied that patch and Memory usage dropped to 35% after rebooting.</p>
]]></description><link>https://forum.netgate.com/post/1089513</link><guid isPermaLink="true">https://forum.netgate.com/post/1089513</guid><dc:creator><![CDATA[MachasaChaira]]></dc:creator><pubDate>Thu, 23 Feb 2023 00:14:27 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 22:12:41 GMT]]></title><description><![CDATA[<p dir="auto">I just applied patch ff715efce5e6c65b3d49dc2da7e1bdc437ecbf12 that was put out by the Netgate crew, see https://redmine.pfsense.org/issues/14016, and rebooted.  Also see the discussion in the thread "23.1 using more RAM" about this patch.</p>
<p dir="auto">After reboot, wired mem dropped from 55% to 33% on my 1100.  I'll check it in the morning to see what happened at 3 AM.</p>
]]></description><link>https://forum.netgate.com/post/1089456</link><guid isPermaLink="true">https://forum.netgate.com/post/1089456</guid><dc:creator><![CDATA[beerguzzle]]></dc:creator><pubDate>Wed, 22 Feb 2023 22:12:41 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 21:01:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a></p>
<p dir="auto">i saw that too, was sure, because I couldn't remember if it was enable in prior version or not.<br />
<a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a>  suggests none of it was not enabled in prior version</p>
<p dir="auto">The change to crontab will for sure stop it and all the other reports it runs too.<br />
again out of the box the way it was configured no one would have seen them anyway ..</p>
<p dir="auto">There are 3 fixes that will alleviate the problem caused by the security reports.<br />
Dealers choice at this point.</p>
<p dir="auto">crontab is likely the best final solution since they say there is nothing else needed.</p>
<p dir="auto">All good. Cheers</p>
]]></description><link>https://forum.netgate.com/post/1089424</link><guid isPermaLink="true">https://forum.netgate.com/post/1089424</guid><dc:creator><![CDATA[jrey]]></dc:creator><pubDate>Wed, 22 Feb 2023 21:01:28 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 21:05:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/defenderllc">@<bdi>defenderllc</bdi></a> said in <a href="/post/1089407">1100 upgrade, 22.05-&gt;23.01, high mem usage</a>:</p>
<blockquote>
<p dir="auto">Netgate suggested commenting out the 3 periodic lines</p>
</blockquote>
<p dir="auto">He made a <a href="https://forum.netgate.com/topic/177886/23-1-using-more-ram/72">patch</a> already.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beerguzzle">@<bdi>beerguzzle</bdi></a> said in <a href="/post/1089396">1100 upgrade, 22.05-&gt;23.01, high mem usage</a>:</p>
<blockquote>
<p dir="auto">Netgate has withdrawn release of 23.01 for smaller boxes.  While they didn't actually say it, they seem to acknowledge that there is a real bug</p>
</blockquote>
<p dir="auto">There were threads about it like <a href="https://forum.netgate.com/topic/177896/sg-2100-23-01-update-failed/48">this one</a>.  Early models of 1100/2100 had a small EFI partition, and the issue is an "out of space" copying to it.  I'm not clear myself if that means "all sold with UFS" or just early models.  I have a 2100 that had an 800K partition and had the problem. New installs and newer devices have ZFS and a 200 MB EFI partition so aren't affected.  Per that thread Netgate was unable to duplicate the issue, at least as of this weekend, but stopped the updates anyway.  A new install will use ZFS and the new file system layout so is unaffected.  One can still request the 23.01 image file and <a href="https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/reinstall-pfsense.html" target="_blank" rel="noopener noreferrer nofollow ugc">reinstall</a> fine.</p>
<p dir="auto">I would normally have waited longer myself, knowing they skipped a FreeBSD version and <a href="https://docs.netgate.com/pfsense/en/latest/development/php-config-arrays.html" target="_blank" rel="noopener noreferrer nofollow ugc">jumped to PHP 8 with lots of coding changes</a>, but was testing the 2100.</p>
]]></description><link>https://forum.netgate.com/post/1089421</link><guid isPermaLink="true">https://forum.netgate.com/post/1089421</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Wed, 22 Feb 2023 21:05:28 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 20:39:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beerguzzle">@<bdi>beerguzzle</bdi></a> said in <a href="/post/1089396">1100 upgrade, 22.05-&gt;23.01, high mem usage</a>:</p>
<blockquote>
<p dir="auto">I have pfblockerng version 3.2.0_2, I will apply the update and see what happens.</p>
</blockquote>
<p dir="auto">it won't change the static memory loss caused by the security reports running, but it certainly has some great features.<br />
I actually did the troubleshooting on the cron issue that is fixed in there.  That was a fun weekend ;-). but all around that is a very good update they have done an excellent job pulling it all together so quickly.</p>
]]></description><link>https://forum.netgate.com/post/1089413</link><guid isPermaLink="true">https://forum.netgate.com/post/1089413</guid><dc:creator><![CDATA[jrey]]></dc:creator><pubDate>Wed, 22 Feb 2023 20:39:17 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 20:32:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jrey">@<bdi>jrey</bdi></a> said in <a href="/post/1089392">1100 upgrade, 22.05-&gt;23.01, high mem usage</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/defenderllc">@<bdi>defenderllc</bdi></a></p>
<p dir="auto">Short answer = yes 100%</p>
<p dir="auto">Long answer, why I disabled the whole thing</p>
<p dir="auto">I used the disable the entire 450.status-security enabled "NO"<br />
and yes all three cases with 100% after with no loss, one of the posts here shows/comments on that.<br />
then I started to break it again to narrow down which specific step was causing it.</p>
<p dir="auto">at the end I just disable the entire security report, unless you make the other changes I documented earlier there is really nothing to see ;-)<br />
have to change from "YES" to "NO"</p>
<p dir="auto">daily_status_security_enable="NO"<br />
weekly_status_security_enable="NO"<br />
monthly_status_security_enable="NO"</p>
<p dir="auto">but the changes in the other thread should also work as well, but they only disable specifically the base audit, pkg checksum and pkgaudit<br />
ie the rest of the security report will still generate, and effectively go nowhere (you'll never see it) in the out of box config  unless you also change the logging options as I documented earlier.</p>
<p dir="auto">honestly in the current state, the system security report is of little value.<br />
For example, one of the checks it run is for "login failures:"  and it hasn't picked up a single one. (and I've fat fingered my password more than once today.)   My NAS picks up the log in failure from the syslog and notifies me almost instantly (within seconds that I can't spell my password)  I've often got the email telling me about that before I've retyped it and actually logged in. LOL</p>
<p dir="auto">maybe when FreeBSD 14 goes -RELEASE there may be value. But for now the value is keeping the memory footprint under 20%  (it not a real goal, it's just where I flat lined before the upgrade) I support 40-50 devices LAN side and memory really never moves much (at 16% right now)</p>
</blockquote>
<p dir="auto">Netgate suggested commenting out the 3 periodic lines in the /etc/crontab file.  <a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a> mentioned that those were not enabled in 22.05.  I just made the edits and rebooted.  We will know for sure tomorrow morning!</p>
]]></description><link>https://forum.netgate.com/post/1089407</link><guid isPermaLink="true">https://forum.netgate.com/post/1089407</guid><dc:creator><![CDATA[DefenderLLC]]></dc:creator><pubDate>Wed, 22 Feb 2023 20:32:16 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 20:26:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beerguzzle">@<bdi>beerguzzle</bdi></a></p>
<p dir="auto">Fair enough,  I'm on a 2100 and no other issues</p>
<p dir="auto">(well except it still does show as registered, but TAC told me that was a backend  issue that would correct itself, when they fix the backend "shortly" that was last week, so I don't know how long "shortly" is.  Not a panic at this point because they also told me it shows as registered on their side and is seeing the correct repo's and package availability etc.  Sure they are swamped.  The joy of releasing new stuff, been there, done that.</p>
<p dir="auto">Cheers</p>
]]></description><link>https://forum.netgate.com/post/1089400</link><guid isPermaLink="true">https://forum.netgate.com/post/1089400</guid><dc:creator><![CDATA[jrey]]></dc:creator><pubDate>Wed, 22 Feb 2023 20:26:46 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 20:12:49 GMT]]></title><description><![CDATA[<p dir="auto">Personally, I'm reluctant to muck with crontab scripts at the moment, especially since Netgate has withdrawn release of 23.01 for smaller boxes.  While they didn't actually say it, they seem to acknowledge that there is a real bug out there that they need to corner.  So, I'm hoping that a 23.02 release might come out soon and solve this issue.</p>
<p dir="auto">BTW, I just noticed that a new version of pfblockerng has appeared in System/Package Manager/Installed Packages.  I have pfblockerng version 3.2.0_2, I will apply the update and see what happens.</p>
]]></description><link>https://forum.netgate.com/post/1089396</link><guid isPermaLink="true">https://forum.netgate.com/post/1089396</guid><dc:creator><![CDATA[beerguzzle]]></dc:creator><pubDate>Wed, 22 Feb 2023 20:12:49 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 20:11:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/defenderllc">@<bdi>defenderllc</bdi></a></p>
<p dir="auto">Short answer = yes 100%</p>
<p dir="auto">Long answer, why I disabled the whole thing</p>
<p dir="auto">I used the disable the entire 450.status-security enabled "NO"<br />
and yes all three cases with 100% after with no loss, one of the posts here shows/comments on that.<br />
then I started to break it again to narrow down which specific step was causing it.</p>
<p dir="auto">at the end I just disable the entire security report, unless you make the other changes I documented earlier there is really nothing to see ;-)<br />
have to change from "YES" to "NO"</p>
<p dir="auto">daily_status_security_enable="NO"<br />
weekly_status_security_enable="NO"<br />
monthly_status_security_enable="NO"</p>
<p dir="auto">but the changes in the other thread should also work as well, but they only disable specifically the base audit, pkg checksum and pkgaudit<br />
ie the rest of the security report will still generate, and effectively go nowhere (you'll never see it) in the out of box config  unless you also change the logging options as I documented earlier.</p>
<p dir="auto">honestly in the current state, the system security report is of little value.<br />
For example, one of the checks it run is for "login failures:"  and it hasn't picked up a single one. (and I've fat fingered my password more than once today.)   My NAS picks up the log in failure from the syslog and notifies me almost instantly (within seconds that I can't spell my password)  I've often got the email telling me about that before I've retyped it and actually logged in. LOL</p>
<p dir="auto">maybe when FreeBSD 14 goes -RELEASE there may be value. But for now the value is keeping the memory footprint under 20%  (it not a real goal, it's just where I flat lined before the upgrade) I support 40-50 devices LAN side and memory really never moves much (at 16% right now)</p>
]]></description><link>https://forum.netgate.com/post/1089392</link><guid isPermaLink="true">https://forum.netgate.com/post/1089392</guid><dc:creator><![CDATA[jrey]]></dc:creator><pubDate>Wed, 22 Feb 2023 20:11:13 GMT</pubDate></item><item><title><![CDATA[Reply to 1100 upgrade, 22.05-&gt;23.01, high mem usage on Wed, 22 Feb 2023 19:41:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jrey">@<bdi>jrey</bdi></a> said in <a href="/post/1089378">1100 upgrade, 22.05-&gt;23.01, high mem usage</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a></p>
<p dir="auto">Yup I went a little further in testing, and pin pointed the exact step.</p>
<p dir="auto">But I also then just disabled the 450.status-security in the config.<br />
as it was configured out of box as (mail root) no one would ever see the output anyway.<br />
following through I also sent the output to log files so in case I might like to look at it one day (NOT)</p>
<p dir="auto">this thread details all the steps I took and at what point it breaks, the settings quoted on the reference thread will do the same as disabling 450.status-security<br />
there is nothing to see there anyway, especially as configured out of box.</p>
<p dir="auto">security_status_baseaudit_enable="NO"<br />
security_status_pkg_checksum_enable="NO"<br />
security_status_pkgaudit_enable="NO"</p>
</blockquote>
<p dir="auto">I am active on that other thread too, but have not had a chance to perform those steps yet.  Did it resolve the issue when you force the daily periodical post reboot?</p>
]]></description><link>https://forum.netgate.com/post/1089379</link><guid isPermaLink="true">https://forum.netgate.com/post/1089379</guid><dc:creator><![CDATA[DefenderLLC]]></dc:creator><pubDate>Wed, 22 Feb 2023 19:41:52 GMT</pubDate></item></channel></rss>