[Snort-users] Snort and high performance networks

Jason Haar Jason.Haar at ...294...
Sun May 23 20:34:06 EDT 2004


Rafael Ortega wrote:

>Hello, All
>
>I'm currently snorting close to 800Mbps with no problem.  What to do with
>the amount of info, is another story.  I tried ACID, but after 24 hours and
>700,000 events registered, the data base becomes too slow, even after
>indexing certain reference fields.
>...
>The sniffer is an Intel Xeon 2.4GHz with 1GB RAM running only snort and
>barnyard.
>
>  
>
How about OS? Also, anything special about the PCI bus and Ethernet card 
choices? (e.g. I don't think standard 33Mhz PCI can do 800Mbs)

You are correct about ACID. I love it - but it really grinds to a halt 
around 100K records

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1





More information about the Snort-users mailing list