Hi,

Since we use pf_ring for packet capturing on our IDS the sys cpu load is quite 
high. On my test system I managed it to push it to around 80% sys with a simple 
ssh session.
On our production system, the system load always hangs on 100%, however 
capturing is performing very well, there is nearly no packet loss even on the 
system with 7 dedicated NICs, so is the high load just normal and I don't need 
to worry about this?

/proc/net/pfring/info:
PF_RING Version     : 4.6.0 ($Revision: 4513$)
Ring slots          : 4096
Slot version        : 12
Capture TX          : No [RX only]
IP Defragment       : No
Transparent mode    : No (mode 2)
Total rings         : 13
Total plugins       : 0

our nic driver: e1000e, pfring-modified version 

regards,

Florian Feucht
_______________________________________________
Ntop-dev mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-dev

Reply via email to