[Snort-users] Where's Waldo?

Thu Oct 11 18:02:35 EDT 2012

The condition mentioned earlyer by Waldo Kitty is called "backlog"

Backlog is a state is a state where you are receiving/generating alot
of unified2 event,
so mutch that even if barnyard2 is reading them its not outputing them
fast enough.

That state was easily observable with barnyard2 2-1.9 if you where
outputing to database on a busy database
or high latency link because of the way that the original port for the
database output was written.

Generating 1 query for every table and querying signatures tables at
every event.

The rewrite of 2-1.10  database output plugin was mainly done to
address that issue and others but now events
are written in a single block and signature query are done only if the
signature was not already in cache. The minimum
 insert throughtput performance has been by 8 to 10 fold if not more
in some cases.

So if you observe backlog on 2-1.10 i would be interested known things like:
1)  what is your backend dbms
2)  whats the network latency betwen your  barnyard2 node
3)  how many events/second you are generating.

I hope this shed some light on previous observation done by the concerned party.


