<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">
<br class="">
<blockquote type="cite" class="">On Sep 5, 2018, at 6:35 PM, Jon Siwek <<a href="mailto:jsiwek@corelight.com" class="">jsiwek@corelight.com</a>> wrote:<br class="">
<br class="">
There's no significant code changes/features planned to get added to<br class="">
the master branch from now until the 2.6-beta gets released (maybe in<br class="">
about a week). Until that happens, please help test the latest master<br class="">
branch and provide any feedback about how it's working if you can.<br class="">
<br class="">
- Jon<br class="">
</blockquote>
<div class=""><br class="">
</div>
Hi again!
<div class=""><br class="">
</div>
<div class="">Just finished the migration to master across the board, and it's looking REALLY good.</div>
<div class=""><br class="">
</div>
<div class="">No crashes, memory is stable, cpu is pretty good. The only thing I noticed is the manager userspace CPU utilization on one cluster</div>
<div class="">jumped up a bit after the switch.</div>
<div class=""><br class="">
</div>
<div class="">This graph shows the system and userspace utilization across an 8 physical node cluster. All the lower lines are the system usage</div>
<div class="">and the higher lines are userspace. The Y axis is cpu seconds per second, so 4 is full 4 cores worth of usage.</div>
<div class=""><br class="">
</div>
<div class="">After the switchover:</div>
<div class=""><br class="">
</div>
<div class="">* the worker userspace cpu utilization was unchanged</div>
<div class="">* the worker system cpu utilization increased a bit, but I believe that is due to more time spent in the myricom driver waiting for packets</div>
<div class="">* the manager system cpu utilization dropped a bunch</div>
<div class="">* the manager userspace cpu increased 1-3x</div>
<div class=""><br class="">
</div>
<div class="">The manager box in this cluster only runs the manager and logger processes, no proxies. It also has something like 20 idle cores,</div>
<div class="">so this isn't a problem at all, but could affect people who run a cluster-in-a-box.</div>
<div class=""><br class="">
<img apple-inline="yes" id="3AE06811-9ADC-4813-9623-B77B200B3365" src="cid:3BF8BC03-721F-44E6-A052-6E1ADA454C02@home" class=""><br class="">
<br class="">
</div>
<div class="">I do seem to be seeing a bunch of reporter errors like</div>
<div class=""><br class="">
</div>
<div class="">Reporter::ERROR string with embedded NUL: "\\x00\\x00\\x00\\x00OPTIONS"</div>
<div class=""><br class="">
</div>
<div class="">but I'm not sure if that is a new thing.</div>
<div class=""><br class="">
</div>
<div class="">— <br class="">
Justin Azoff<br class="">
<br class="">
</div>
</body>
</html>