This is a discussion on Re: [Snort-users] Snort and high performance networks within the Snort forums, part of the System Security and Security Related category; Rafael Ortega wrote: >Hello, All > >I'm currently snorting close to 800Mbps with no problem. What to ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
Rafael Ortega wrote:
>Hello, All > >I'm currently snorting close to 800Mbps with no problem. What to do with >the amount of info, is another story. I tried ACID, but after 24 hours and >700,000 events registered, the data base becomes too slow, even after >indexing certain reference fields. >... >The sniffer is an Intel Xeon 2.4GHz with 1GB RAM running only snort and >barnyard. > > > How about OS? Also, anything special about the PCI bus and Ethernet card choices? (e.g. I don't think standard 33Mhz PCI can do 800Mbs) You are correct about ACID. I love it - but it really grinds to a halt around 100K records -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |