Sekoia FRA1 incident

CTI database cluster restart due to performance issues

Major Resolved View vendor source →

Sekoia FRA1 experienced a major incident on June 17, 2025 affecting CTI Search and CTI Feed (API) and 1 more component, lasting 17h 11m. The incident has been resolved; the full update timeline is below.

Started
Jun 17, 2025, 09:37 PM UTC
Resolved
Jun 18, 2025, 02:49 PM UTC
Duration
17h 11m
Detected by Pingoru
Jun 17, 2025, 09:37 PM UTC

Affected components

CTI SearchCTI Feed (API)CTI Feed (TAXII)CTI Feed (MISP)

Update timeline

  1. investigating Jun 17, 2025, 09:37 PM UTC

    We are currently addressing an issue with our FRA1 CTI database cluster. To resolve the situation, we are performing a full restart of the database cluster. This operation may take some time. During this period, customers may experience temporary disruptions or degraded performance. We apologize for any inconvenience and will provide updates as more information becomes available.

  2. monitoring Jun 18, 2025, 02:44 AM UTC

    We have made significant progress in addressing the issue with our CTI database cluster. We are also implementing measures to balance memory usage across nodes. Please note that we have taken precautionary measures to ensure stability. We appreciate your understanding and will continue to provide updates when this issue has been addressed durably.

  3. resolved Jun 18, 2025, 02:49 PM UTC

    We have successfully resolved the issue with our FRA1 CTI database cluster. The system is now stable after implementing measures to balance memory usage across nodes and restarting the cluster. We have also installed two new nodes and migrated heavy-duty shards to these servers. As a result, we were able to rollback temporary measures and bring the system back to normal operation. We appreciate your understanding throughout this incident and apologize for any inconvenience caused.