Snort mailing list archives

RE: Database performance question (MySQL or PostgreSQL?)


From: "Marc Quibell" <mquibell () fbfs com>
Date: Fri, 26 Sep 2003 09:02:33 -0500




Hi Jyri,
I've always had that problem, except my CPU is a bit bigger than yours, I think
it's a 750 MHZ. Anyways, I noticed the CPU jumps to 100% when I have over
100,000 (or a large number) alerts and I start deleting them. It takes forever
and usually times out b4 it can delete them all (so I increased the timeout
value).

I have another machine sitting next to it that had dual processors and more
memory, and it was only running Snort, so I swapped hardware between the two and
added the multi-processor kernel. Now when I look at the processor utilization,
both processors are still hit hard, but not topped-out, and the memory usage is
much better, The result is that I can delete 1000's of alerts, much faster.

Marc






-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: