This repository has been archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 521
AF PACKET
Doug Burks edited this page Jan 31, 2019
·
7 revisions
Starting in securityonion-setup - 20120912-0ubuntu0securityonion285
, running Setup will configure Suricata and Bro to use AF_PACKET. (Installations already configured for PF_RING will continue to use PF_RING.)
If you want to change the number of AF_PACKET instances after running Setup, you can do the following.
- Stop sensor processes:
sudo so-suricata-stop
- Edit
/etc/nsm/$HOSTNAME-$INTERFACE/sensor.conf
and change theIDS_LB_PROCS
variable to desired number of cores. - Start sensor processes:
sudo so-suricata-start
so-suricata-start
automatically copies $IDS_LB_PROCS into suricata.yaml and then Suricata creates the appropriate number of AF_PACKET workers.
For Bro, you would do the following:
- Stop bro:
sudo so-bro-stop
- Edit
/opt/bro/etc/node.cfg
and change thelb_procs
variable to the desired number of cores.
- Start bro:
sudo so-bro-start
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs