[Bro] Question about capture loss script vs. broctl netstats

Michal Purzynski michal at rsbac.org
Thu Jun 27 14:15:17 PDT 2013


On 6/27/13 8:38 PM, Seth Hall wrote:
> On Jun 27, 2013, at 2:21 PM, Derek Banks <itsecderek at gmail.com> wrote:
>
>> Thanks for all the responses.  I put an Intel Pro 1000 in this morning and still using PF_Ring.  I three hours of running Bro, I don't see any reported packet loss.  Looks like the Broadcom Card was most likely the problem.
> Oh yeah, I would never use Broadcom for sniffing.  I've had way too many problems with them.
Use Intel or ... use Intel. Too many stability problems with other 
vendors, and all of them resolved using X520.

Unless you can afford DAG or similar of course.
>
>    .Seth
>
> --
> Seth Hall
> International Computer Science Institute
> (Bro) because everyone has a network
> http://www.bro.org/
>
>
> _______________________________________________
> Bro mailing list
> bro at bro-ids.org
> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/bro




More information about the Bro mailing list