On Wed, Aug 12, 2020 at 6:34 AM Justin Azoff <justin(a)corelight.com> wrote:
On Tue, Aug 11, 2020 at 9:25 PM Darren S.
Hoping to understand the data in PacketFilter::Dropped_packets notices
better. What do each of the counts indicate?
Wondering because I have a small percentage of notices from a variety
of sensors that are logging the following in the notices, and the
counts end up being too large of integers for some post-processing
utilities to help compute some metrics on. I suspect that these come
from Bro 2.6 sensors. Examples:
18446744069482849436 packets dropped after filtering,
18446744069489230937 received, 6381501 on link
Looks like a driver problem or something odd going on... something
confusing a 32bit value for a 64bit one. What sort of platform is
Verified the following:
Likely running as VMware guests
- e1000 (version 7.3.21-k8-NAPI)
- vmxnet3 (version 22.214.171.124-k-NAPI)
You should upgrade to zeek. Bro 2.6 is missing years of features,
performance, and security fixes at this point.
This is occurring hopefully shortly.