Snort mailing list archives

Munin plugins for Snort perfmon...


From: Edward Bjarte Fjellskål <edward () linpro no>
Date: Fri, 19 Dec 2008 13:33:11 +0100

Hi,

In light of having a performance issue on one of my sensors,
wondering how to go about it, I came by a forum thread:
http://www.snort.org/reg-bin/forums.cgi?forum_id=1&topic_id=6754
and I did some quick munin plugins...

I have searched the web for such graphs for some time, with
no luck. I hope these will be useful to the community.

The graphs are generated by munin, which uses rrd-tool.
The graphs are updated each 5 minutes (depending on your
preprocessor perfmonitor settings though...)



Plungis for:

Drop Rate (%), Pattern Matching (%), Traffic speed (Mbits/s),
Alerts (per second), Avg KBytes/pkt and Avg Pkts/sec.



Plugins are found here:
http://download.gamelinux.org/snort/

Picture of how the trend graphs look like here:
http://download.gamelinux.org/snort/Snort-Munin-Plugins.png

Blog post about it here:
http://www.gamelinux.org/?p=32
Thoughts and comments are welcome :)

An expert comment on the forum thread above would be nice :)

Hacky Xmas and such...

-- 
http://www.gamelinux.org/
http://munin.projects.linpro.no/

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: