[Bro] Emerging Threats signatures on Bro ids ?

Seth Hall seth at icir.org
Mon Aug 13 12:36:15 PDT 2012


On Aug 13, 2012, at 5:29 PM, rmkml <rmkml at yahoo.fr> wrote:

> ok I have started very small bench on my local network: (wget, one cnx)


You need to do this with a decent sized tracefile (>1GB) of mixed traffic and run Bro with the "time" command to see how long it takes for it to analyze the full file.  I suspect the performance degradation will become much more obvious there.

  .Seth

--
Seth Hall
International Computer Science Institute
(Bro) because everyone has a network
http://www.bro-ids.org/





More information about the Bro mailing list