<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Snort cpu usage</title><link>https://community.sophos.com/utm-firewall/f/network-protection-firewall-nat-qos-ips/40032/snort-cpu-usage</link><description>v8.1 how can i have snort only run one instance instead of the 4 it&amp;#39;s trying ot run now. I don&amp;#39;t want snort to be trowing my cpu into the ionosphere..[:)]</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137608?ContentTypeID=1</link><pubDate>Fri, 04 Mar 2011 01:24:49 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c8bc38b2-3bd2-4c34-8365-41d21fb790a0</guid><dc:creator>BarryG</dc:creator><description>FWIW,&amp;nbsp;I&amp;nbsp;did&amp;nbsp;some&amp;nbsp;tests&amp;nbsp;on&amp;nbsp;my&amp;nbsp;Atom&amp;nbsp;n270&amp;nbsp;(1&amp;nbsp;core&amp;nbsp;with&amp;nbsp;HT)&amp;nbsp;@&amp;nbsp;home&amp;nbsp;with&amp;nbsp;iperf;&amp;nbsp;running&amp;nbsp;snort&amp;nbsp;with&amp;nbsp;1&amp;nbsp;or&amp;nbsp;2&amp;nbsp;threads&amp;nbsp;made&amp;nbsp;no&amp;nbsp;difference;&amp;nbsp;I&amp;nbsp;tried&amp;nbsp;running&amp;nbsp;iperf&amp;nbsp;from&amp;nbsp;multiple&amp;nbsp;client&amp;nbsp;PCs&amp;nbsp;(against&amp;nbsp;1&amp;nbsp;server)&amp;nbsp;as&amp;nbsp;well.&amp;nbsp;I&amp;#39;m&amp;nbsp;guessing&amp;nbsp;HyperThreading&amp;nbsp;doesn&amp;#39;t&amp;nbsp;help&amp;nbsp;snort.&lt;br /&gt;&lt;br /&gt;If&amp;nbsp;one&amp;nbsp;had&amp;nbsp;multiple&amp;nbsp;CPU&amp;nbsp;cores&amp;nbsp;with&amp;nbsp;HT,&amp;nbsp;would&amp;nbsp;there&amp;nbsp;be&amp;nbsp;a&amp;nbsp;way&amp;nbsp;to&amp;nbsp;pin&amp;nbsp;snort&amp;nbsp;to&amp;nbsp;physical&amp;nbsp;CPUs&amp;nbsp;only?&amp;nbsp;e.g.&amp;nbsp;if&amp;nbsp;you&amp;nbsp;have&amp;nbsp;2&amp;nbsp;cores&amp;nbsp;each&amp;nbsp;with&amp;nbsp;HT,&amp;nbsp;resulting&amp;nbsp;in&amp;nbsp;4&amp;nbsp;&amp;#39;cpus&amp;#39;,&amp;nbsp;could&amp;nbsp;you&amp;nbsp;set&amp;nbsp;snort&amp;nbsp;to&amp;nbsp;2&amp;nbsp;threads&amp;nbsp;and&amp;nbsp;get&amp;nbsp;it&amp;nbsp;to&amp;nbsp;run&amp;nbsp;on&amp;nbsp;each&amp;nbsp;core?&lt;br /&gt;&lt;br /&gt;Also,&amp;nbsp;I&amp;nbsp;found&amp;nbsp;&lt;b&gt;afcd&lt;/b&gt;&amp;nbsp;to&amp;nbsp;be&amp;nbsp;almost&amp;nbsp;as&amp;nbsp;much&amp;nbsp;of&amp;nbsp;a&amp;nbsp;bottleneck&amp;nbsp;as&amp;nbsp;snort;&amp;nbsp;perhaps&amp;nbsp;it&amp;nbsp;could&amp;nbsp;use&amp;nbsp;some&amp;nbsp;tuning&amp;nbsp;too?&lt;br /&gt;&lt;br /&gt;Performance&amp;nbsp;results:&amp;nbsp;(tested&amp;nbsp;7.509&amp;nbsp;with&amp;nbsp;iperf&amp;nbsp;from&amp;nbsp;VLAN&amp;nbsp;LAN&amp;nbsp;to&amp;nbsp;VLAN&amp;nbsp;DMZ,&amp;nbsp;on&amp;nbsp;a&amp;nbsp;NetGear&amp;nbsp;GS108T&amp;nbsp;gigE&amp;nbsp;&amp;#39;smart&amp;#39;&amp;nbsp;switch,&amp;nbsp;eth1&amp;nbsp;locked&amp;nbsp;at&amp;nbsp;1000Full)&lt;br /&gt;440mbps&amp;nbsp;PacketFilter&amp;nbsp;only&lt;br /&gt;92mbps&amp;nbsp;afcd&amp;nbsp;(flow&amp;nbsp;classifier)&amp;nbsp;IM&amp;nbsp;and/or&amp;nbsp;P2P&amp;nbsp;(performance&amp;nbsp;is&amp;nbsp;the&amp;nbsp;same&amp;nbsp;with&amp;nbsp;1&amp;nbsp;or&amp;nbsp;both&amp;nbsp;enabled)&lt;br /&gt;65mbps&amp;nbsp;snort&amp;nbsp;(5386&amp;nbsp;IPS&amp;nbsp;rules&amp;nbsp;Active)&amp;nbsp;(same&amp;nbsp;with&amp;nbsp;1&amp;nbsp;or&amp;nbsp;2&amp;nbsp;threads)&lt;br /&gt;53mbps&amp;nbsp;snort&amp;nbsp;+&amp;nbsp;afcd&lt;br /&gt;&lt;br /&gt;iperf&amp;nbsp;client&amp;nbsp;-&amp;nbsp;Dell&amp;nbsp;D420&amp;nbsp;Laptop&amp;nbsp;(Broadcom&amp;nbsp;gigE&amp;nbsp;NIC)&amp;nbsp;running&amp;nbsp;Fedora&lt;br /&gt;iperf&amp;nbsp;server&amp;nbsp;-&amp;nbsp;Dell&amp;nbsp;GX280&amp;nbsp;(Intel&amp;nbsp;gigE&amp;nbsp;NIC)&amp;nbsp;running&amp;nbsp;CentOS&lt;br /&gt;&lt;br /&gt;Barry&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137607?ContentTypeID=1</link><pubDate>Fri, 21 Jan 2011 15:13:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8e61a741-51b3-47c2-a92c-bc3cdf2d8b68</guid><dc:creator>William Warren</dc:creator><description>nods&amp;nbsp;i&amp;nbsp;restricted&amp;nbsp;it&amp;nbsp;to&amp;nbsp;2&amp;nbsp;of&amp;nbsp;my&amp;nbsp;4&amp;nbsp;threads&amp;nbsp;then.,,[:)]&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137606?ContentTypeID=1</link><pubDate>Fri, 21 Jan 2011 15:03:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:22c11c81-d468-4e70-8c80-de0ba64b4655</guid><dc:creator>BarryG</dc:creator><description>Yes.&lt;br /&gt;&lt;br /&gt;Barry&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137605?ContentTypeID=1</link><pubDate>Thu, 20 Jan 2011 18:49:47 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cf5bcce4-986b-4918-bbbb-f8c330ecffce</guid><dc:creator>William Warren</dc:creator><description>can&amp;nbsp;other&amp;nbsp;integers&amp;nbsp;be&amp;nbsp;used&amp;nbsp;as&amp;nbsp;well&amp;nbsp;like&amp;nbsp;2&amp;nbsp;or&amp;nbsp;3?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137604?ContentTypeID=1</link><pubDate>Thu, 20 Jan 2011 07:34:51 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9aa1a3a5-33b6-41e9-b0fd-b0508b2f0a86</guid><dc:creator>Scott_Klassen</dc:creator><description>Very&amp;nbsp;cool.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137603?ContentTypeID=1</link><pubDate>Thu, 20 Jan 2011 07:23:59 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ddc18a61-776b-4620-88ce-40e47dc28579</guid><dc:creator>da_merlin</dc:creator><description>You&amp;nbsp;have&amp;nbsp;to&amp;nbsp;connect&amp;nbsp;via&amp;nbsp;ssh&amp;nbsp;to&amp;nbsp;your&amp;nbsp;ASG&amp;nbsp;and&amp;nbsp;execute&amp;nbsp;the&amp;nbsp;following&amp;nbsp;command:&lt;br /&gt;cc&amp;nbsp;set&amp;nbsp;ips&amp;nbsp;num_instances&amp;nbsp;1&lt;br /&gt;&lt;br /&gt;This&amp;nbsp;will&amp;nbsp;limit&amp;nbsp;the&amp;nbsp;snort&amp;nbsp;instances&amp;nbsp;on&amp;nbsp;your&amp;nbsp;ASG&amp;nbsp;to&amp;nbsp;1&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&amp;nbsp;Ulrich&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137602?ContentTypeID=1</link><pubDate>Thu, 20 Jan 2011 01:10:52 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6317229b-9738-4e80-9f78-f5803d99163b</guid><dc:creator>William Warren</dc:creator><description>no&amp;nbsp;i&amp;nbsp;do&amp;nbsp;not...only&amp;nbsp;two&amp;nbsp;but&amp;nbsp;i&amp;nbsp;do&amp;nbsp;have&amp;nbsp;4&amp;nbsp;procs.&amp;nbsp;&amp;nbsp;I&amp;nbsp;know&amp;nbsp;it&amp;nbsp;always&amp;nbsp;spawns&amp;nbsp;2&amp;nbsp;but&amp;nbsp;i&amp;#39;ve&amp;nbsp;seen&amp;nbsp;4.&amp;nbsp;&amp;nbsp;I&amp;nbsp;only&amp;nbsp;need&amp;nbsp;one&amp;nbsp;snort&amp;nbsp;instance..how&amp;nbsp;can&amp;nbsp;i&amp;nbsp;trim&amp;nbsp;it&amp;nbsp;back?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Snort cpu usage</title><link>https://community.sophos.com/thread/137601?ContentTypeID=1</link><pubDate>Thu, 20 Jan 2011 01:08:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:15c96ac2-4378-44ae-859c-8fbae593c32c</guid><dc:creator>Scott_Klassen</dc:creator><description>How&amp;nbsp;odd.&amp;nbsp;&amp;nbsp;By&amp;nbsp;chance&amp;nbsp;do&amp;nbsp;you&amp;nbsp;have&amp;nbsp;4&amp;nbsp;local&amp;nbsp;networks&amp;nbsp;set&amp;nbsp;in&amp;nbsp;IPS?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>