OS settings¶
This page provides recommended OS, BIOS, and system configuration settings for running KX Sensors on Linux.
KX recommends configuring the OS as follows.
BIOS¶
- Enable hyperthreading.
- Enable NUMA.
- Set CPU power settings to performance (instead of default BIOS setting of balanced).
- Turn off all mitigations (Sceptre, etc.) on startup. Consult your hardware manufacturer’s guides.
System configuration¶
Review and tune the following system configuration values based on available RAM, then deploy them to all servers. Deploy them to a file named /etc/sysctl.d/99-kxs-sysctl.conf to keep all Sensors-related settings centralized in a dedicated file.
[sysctl]
# Important for every KXS deployment
vm.swappiness = 0
# Related to RAM; these values are based on system w/ 4 TB
vm.max_map_count = 31250000
vm.dirty_bytes = 335544320
vm.dirty_background_bytes = 5368709120
vm.dirty_expire_centisecs = 500
vm.dirty_writeback_centisecs = 450
vm.dirty_ratio = 0
vm.min_free_kbytes = 100000000
vm.vfs_cache_pressure = 250
vm.watermark_scale_factor = 400
# Network Tuning
net.core.netdev_max_backlog = 600000
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 100000
net.ipv4.tcp_ecn = 1
net.ipv4.tcp_mtu_probing = 1
net.core.optmem_max = 25165824
net.core.somaxconn = 4096
net.ipv4.tcp_max_syn_backlog = 10240
net.ipv4.tcp_window_scaling = 1
net.ipv4.ip_local_port_range = 15000 65535
# Maximum receive socket buffer size.
net.core.rmem_max = 25165824
net.core.rmem_default = 25165824
# Maximum send socket buffer size.
net.core.wmem_max = 25165824
net.core.wmem_default = 25165824
net.ipv4.tcp_rmem = 1464844 12582912 25165824
net.ipv4.tcp_wmem = 1464844 12582912 25165824
net.ipv4.udp_rmem_min = 131072
net.ipv4.udp_wmem_min = 131072
# Increase max number of file descriptors.
# (Also scales w/ RAM.)
fs.file-max = 5000000
# Review and tune this number.
# It should be the total number of RAM required by Sensors on average,
# divided by size of huge pages. (Common sizes are 2 MB or 1 GB.)
vm.nr_hugepages = 30
# Also note that /sys/kernel/mm/transparent_hugepage/defrag should be set to never
# Disk readahead settings; this needs to be edited for the specific disks that make up /data (or wherever HDB files are)
[disk-md125]
Type = disk
Devices = md125
Readahead = 4096
Time synchronization¶
All servers must have time synchronization enabled via an NTP client/daemon, since the logic behind high-availability failovers relies on this. This requirement doesn't apply to servers hosting external SAPI clients.
Disable mitigations¶
In addition to the BIOS setting, turn off mitigations such as Sceptre in the OS on startup. For more information, see the Red Hat guidelines.
Update network drivers¶
If applicable, update your network drivers. Intel Ethernet adapters (nearly all of the 55x line) have a known bug when using Flow Director. To work around this, enable ntuple filtering. For more information, see the Red Hat documentation.