Snort mailing list archives
Benchmarking snort
From: "Michael L. Artz" <dragon () october29 net>
Date: Thu, 17 Apr 2003 22:02:00 -0400
Has any work been done benchmarking snort against the number of rules in your config and the preprocessors that you turn on? More specifically, if I take a single snort process with 1000 rules and break that into 2 snort processes running 500 rules (running on the same box) can I expect about the same loading of the box, minus a bit of memory overhead? In the same vein, if I can currently handle 100Mbps with a snort process with 1000 rules, what speeds will I be able to reliably handle if I decrease the ruleset to 500?
Basically, I am trying to get at how to load-balance several snort sensors across a network. Would the best way be to decrease the traffic load by policy routing different sessions to different snort boxes, or putting another snort box on the same network and dividing the current ruleset between the two snort boxes?
Finally, what is the fastest that anyone has reliably run snort, and how many rules/preprocessors were turned on when you did this?
Any info/pointers/flames are appreciated. Thanks -Mike ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Benchmarking snort Michael L. Artz (Apr 17)
- Re: Benchmarking snort Bennett Todd (Apr 17)