At Aspyn Information Services, we rely on Wazuh for robust security monitoring, but even the best tools require proactive maintenance. Recently, we encountered a situation where a Wazuh SIEM instance on a Linux VM became completely unresponsive. The culprit? Disk space exhaustion, specifically caused by the vulnerability detection feed.

When your disk fills up to 100%, services like the Wazuh Dashboard stop loading because the underlying database and OS cannot write essential logs or temporary files. Here is how we diagnosed, cleaned, and expanded our storage to bring the SIEM back to life.

Finding the Hidden Bloat

After noticing the dashboard was unreachable, we checked the disk usage. Sure enough, the root partition was at 100% capacity:

df -h /
# Output: /dev/sda1 25G 25G 20K 100% /

Using du -sh /var/ossec/queue/vd/feed, we identified that the vulnerability feed was consuming almost half of our available disk space.

Breaking Through the “Full Disk” Barrier

When a disk is completely full, even simple commands like rm -rf * can fail because the system needs space to process the glob. If you find yourself in this situation, do not try to use wildcards. Instead, use the find command to delete files directly without needing shell expansion:

sudo find /var/ossec/queue/vd/feed -type f -delete

We also freed up additional space by clearing older log files. Once we regained about 48% of our disk space, the system was stable enough to perform a permanent fix.

Expanding Storage

Since the Wazuh vulnerability feed is a critical component that will inevitably grow, we performed a permanent storage upgrade:

1. Shutdown: Safely shut down the Linux VM.
2. Hyper-V Expansion: Expanded the virtual hard disk (VHD) in Hyper-V from 25 GB to 75 GB.
3. Boot & Auto-Expand: After booting back up, the Wazuh distribution automatically detected the extra space and expanded the partition to fill the new 75 GB capacity.

Verification & Service Recovery

Once the disk was expanded, we ensured all core services were operational:

sudo systemctl status wazuh-manager wazuh-indexer wazuh-dashboard --no-pager

With services showing green, we re-enabled the vulnerability detection feed and restarted the manager (sudo systemctl restart wazuh-manager). Your SIEM should now be back to monitoring your environment with room to grow.

Proactive IT Management

SIEM platforms provide incredible visibility, but they are also storage-hungry. Regular monitoring of your log and feed directories is a standard part of our maintenance at Aspyn.

For more insights on keeping your IT systems optimized, check out our recent posts on (https://aspyn.com/blog/).

Need professional support to streamline your security infrastructure? Contact Aspyn Information Services (https://aspyn.com/) today. Let’s make your IT work for you.

author avatar
Aspyn IT Specialist
Our IT Ninja hunts Bugs and Challenges in order to keep your Nanaimo Business Running Smoothly.