[Oisf-users] What does it means??

C. L. Martinez carlopmart at gmail.com
Wed Oct 9 13:14:30 UTC 2013


On Wed, Oct 9, 2013 at 1:10 PM, Peter Manev <petermanev at gmail.com> wrote:
>>> --
>>
>> More or less, same numbers using autofp runmode:
>>
>> -------------------------------------------------------------------
>> Date: 10/9/2013 -- 13:05:07 (uptime: 0d, 00h 03m 18s)
>> -------------------------------------------------------------------
>> Counter                   | TM Name                   | Value
>> -------------------------------------------------------------------
>> capture.kernel_packets    | RxPcapem41                | 2283902
>> capture.kernel_drops      | RxPcapem41                | 1717154
>> capture.kernel_ifdrops    | RxPcapem41                | 0
>> _______________________________________________
>
> What is your start line?
> Have you tried with just one interface and then gradually add all 5?
>

I am sniffing only in one interface, not in 5 ...

Command line is:

/usr/local/bin/suricata -i em4 -c /data/config/etc/idpsuricata/suricata.yaml -D



More information about the Oisf-users mailing list