On 2014-05-05 at 22:22:01 +0200, Michal Purzynski
wrote:
> Same story.
>
> root@nsm1:~# ./netsniff-ng -i eth2 -o
> /nsm/sensor_data/nsm1-eth2/dailylogs/2014-04-30/ --user 2551 --group
> 2551 -s --prefix snort.log. --verbose --ring-size 5GiB --interval
> 1500MiB --mmap --filter /etc/nsm/nsm1-eth2
Same story.
root@nsm1:~# ./netsniff-ng -i eth2 -o
/nsm/sensor_data/nsm1-eth2/dailylogs/2014-04-30/ --user 2551 --group
2551 -s --prefix snort.log. --verbose --ring-size 5GiB --interval
1500MiB --mmap --filter /etc/nsm/nsm1-eth2/bpf-pcap.ops
pcap file I/O method: mmap
RX,V3: 5120.00 MiB, 81920
On 2014-04-30 at 21:20:03 +0200, Michal Purzynski
wrote:
>
> >There's a fix now in the master branch of netsniff-ng.git [1]. Can you
> >confirm that this fixes the issue for you? Does it influence the
> >"losslessness" of your setup if you specify large ring sizes?
> >
> >[1] https://github.com/