[Snort-users] Can I 'nice' snort process?

Kris Kennaway kris at ...1402...
Thu Jan 10 11:29:04 EST 2002


On Thu, Jan 10, 2002 at 10:03:16AM -0800, Tran, John wrote:
> I'm running snort on one of my web servers as a local IDS (don't ask me why,
> let's just go along w/ it for now..) and it takes up massive amounts of CPU
> (40%), which can be expected considering it's a large amount of traffic.  It
> was suggested to me to run 'nice' on the process to throttle it's CPU usage,
> but I'm pretty sure throttling snort will cause it to drop a lot of packets.
> Is this true?

It's using that amount of CPU because that's the amount of CPU it
needs to use to monitor all that traffic.  Consider doing things to
reduce the snort workload or the impact on the server.

Kris
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 230 bytes
Desc: not available
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020110/62087956/attachment.sig>


More information about the Snort-users mailing list