Snort mailing list archives

Benchmarking snort


From: "Michael L. Artz" <dragon () october29 net>
Date: Thu, 17 Apr 2003 22:02:00 -0400

Has any work been done benchmarking snort against the number of rules in your config and the preprocessors that you turn on? More specifically, if I take a single snort process with 1000 rules and break that into 2 snort processes running 500 rules (running on the same box) can I expect about the same loading of the box, minus a bit of memory overhead? In the same vein, if I can currently handle 100Mbps with a snort process with 1000 rules, what speeds will I be able to reliably handle if I decrease the ruleset to 500?

Basically, I am trying to get at how to load-balance several snort sensors across a network. Would the best way be to decrease the traffic load by policy routing different sessions to different snort boxes, or putting another snort box on the same network and dividing the current ruleset between the two snort boxes?

Finally, what is the fastest that anyone has reliably run snort, and how many rules/preprocessors were turned on when you did this?

Any info/pointers/flames are appreciated.

Thanks
-Mike



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: