[Snort-users] Snort in a cluster

Rodrigo Ramos rodrigo.ramos at ...11361...
Fri Jul 9 07:38:03 EDT 2004


We have installed some snort sensors doing logging on postgresql/mysql
in machines with 4 processors (snort gets one), 1 Gb (RAM), some scsi
disks and Gigabit interfaces to monitor some very big traffic. Before we
get at this configuration we tried some others, but we did not have
Today we are working on a smaller Linux-kernel keep on going with other

IMHO, you may start your snort, configure it as best as you can and
monitor it with the top program and with the performance monitor. The
power of you machine will mostly depend on the configuration (rules and
preprocessors) and on traffic.

Best Regards,
Rodrigo Ramos

On Fri, 2004-07-09 at 08:41, Luis Claudio Rodrigues da Silveira wrote:
> Hi all,
> is it possible to setup a beowulf cluster running many snort sensors
> at once? Is there any advantage in terms of performance on packet
> processing??
> Thanks in advance,
> Luis Claudio R da Silveira

More information about the Snort-users mailing list