On Wed, Aug 12, 2020 at 6:34 AM Justin Azoff <justin(a)corelight.com> wrote:
On Tue, Aug 11, 2020 at 9:25 PM Darren S.
<phatbuckett(a)gmail.com> wrote:
Hoping to understand the data in PacketFilter::Dropped_packets notices
better. What do each of the counts indicate?
Wondering because I have a small percentage of notices from a variety
of sensors that are logging the following in the notices, and the
counts end up being too large of integers for some post-processing
utilities to help compute some metrics on. I suspect that these come
from Bro 2.6 sensors. Examples:
18446744069482849436 packets dropped after filtering,
18446744069489230937 received, 6381501 on link
Looks like a driver problem or something odd going on... something
confusing a 32bit value for a 64bit one. What sort of platform is
this on?
Verified the following:
CentOS 7
Likely running as VMware guests
NIC drivers:
- e1000 (version 7.3.21-k8-NAPI)
- vmxnet3 (version 1.4.16.0-k-NAPI)
You should upgrade to zeek. Bro 2.6 is missing years of features,
performance, and security fixes at this point.
This is occurring hopefully shortly.
--
Darren Spruell
phatbuckett(a)gmail.com