Skip to main content
Question

Running antivirus in Linux with a Stream worker?

  • March 11, 2025
  • 12 replies
  • 1 view

Hello all, some customer is asking to have an antivirus (!!?!?!?) on the Linux server running a Cribl Stream worker. I found some recommendations for Edge in the documentation, but nothing for Stream. Is it supported, for Stream, having such a configuration? thanks a lot

12 replies

David Maislin

  • Author
  • Employee
  • March 11, 2025

Thanks David. So this is applicable also for a distributed deployment.


David Maislin

<#C01BM8PU30V|docs> <@U03CJ90F91A&gt; perhaps we should also add this info to our distributed deployment pages too.


David Maislin

Yes


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

That is likely depending a LOT on the actual AV used and it's config


  • Author
  • Employee
  • March 11, 2025

thanks again. Do you have some performance numbers, how much degraded is the cribl system using this configuration?


  • Author
  • Employee
  • March 11, 2025

Yes, it makes sense


  • Employee
  • March 11, 2025

From working endpoint security before, I can tell you that they need antivirus on all the things all the time or auditors get upset :disappointed:


  • Employee
  • March 11, 2025

Lack of AV on a linux server can be mitigated by a subset of selinux, file integrity tests, root kit detectors, good monitoring, and especially auditable config. Flies with our auditors.


  • Employee
  • March 11, 2025

The ability to destroy and rebuild a node in minutes doesn't hurt either.


  • Author
  • Employee
  • March 11, 2025

yes, selinux can be a good idea, but no one on the customer side is able to manage that. :disappointed:


  • Employee
  • March 11, 2025

Oh, that does complicate matters. /condolences