I'm having a weird issue with the latest pf_ring that allows user specified snaplen/caplen to tell pf_ring what the bucket length should be. Everything works fine until I restart one of the apps argus which has a smaller snaplen than snort and daemonlogger both with a snaplen of 1515. Once I do this both deamonlogger and snort start to only capture 96 bytes of traffic that is specified as the argus snaplen. If I change the argus snaplen to to 1515 everything is fine, but I don't want to do that as the boxes are overtaxed as it is, and I need to roll the argus files via cron daily....
Regards, Will _______________________________________________ Ntop-dev mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop-dev
