[Snort-users] Snort 2.9, RHEL 5 and afpacket DAQ

Ralf Spenneberg ralf at ...8096...
Tue Oct 19 01:39:34 EDT 2010


Hi Russ,

Am Montag, den 18.10.2010, 15:36 -0400 schrieb Russ Combs:
> Check the DAQ distro README for how to use this option:
> --daq-var buffer_size_mb=<#MB>
> You pass that to Snort which gives it to afpacket.

Thanks a lot for the suggestion, but Looking at the source it should use
a default of 128M if nothing is specified.

Anyway. I played around with the option and apparently I can set it to
49M but not more on this system. Therefore the default did not work!
System:
RHEL5, 4GB, 64bit Kernel: 2.6.18-194.el5

Any clue what might be the restricting factor? Oh, by the way using
PCAP-FRAMES I can use a 2GB ring buffer, so it must be some special
restriction to the afpacket ringbuffer.

Any ideas? Anybody else using the feature on RHEL/CentOS?

Ralf








More information about the Snort-users mailing list