[Bro-Dev] manager crash

Gregor Maier gregor at icir.org
Mon Sep 26 09:51:04 PDT 2011


On 9/26/11 9:25 , Seth Hall wrote:
>
> On Sep 26, 2011, at 11:59 AM, Martin Holste wrote:
>
>> Well, there is high CPU and high volume almost all of the time, and
>> all of the workers are still up and running, so this seems to be a
>> volume issue.
>
>
> Is your weird.log file oddly large?  I've been seeing communications overload occasionally that is in part due to a lot of weird log messages.  I'm becoming really tempted to turn off weird messages but measure some of them through the metrics framework to find where there might be issues (due to checksum offloading, async routing, load balancing problems etc, abundance of out of order traffic, etc).


FWIW,
I often get tons of weirds from the DNS scripts. (The scripts appear to 
get confused with the number of answers to expect)

cu
gregor

-- 
Gregor Maier
<gregor at icir.org>  <gregor at icsi.berkeley.edu>
Int. Computer Science Institute (ICSI)
1947 Center St., Ste. 600
Berkeley, CA 94704, USA
http://www.icir.org/gregor/


More information about the bro-dev mailing list