mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-03 21:14:44 +02:00
Result checks walked dispatch records oldest-first with a cap of five lookups per pass, counting records whose push was still running. Five long-running pushes therefore used every slot on every 15s pass and newer, finished pushes were not reported until one cleared. Check the least recently checked records first and back off on pushes that are still running (30s for the first two minutes, then age/4 up to 5 minutes), recording checked_at in the dispatch record. Catch any exception when writing a dispatch record so a failed write cannot skip intent cleanup and re-dispatch the same intents every pass. Log both output streams when no jid is found, and stop logging a traceback when a record has already been removed. Scope the test's salt mock to the drainer import. Run from the repo root, 'salt' resolves to this repo's salt/ directory as a namespace package, so setdefault left it in place and test_load_push_cfg failed. Verified on a 3.4.0 managersearch + sensor: a pushed highstate with soc and telegraf pushes dispatched into it all reported success, with 25 result lookups across the three pushes instead of one per record per pass.