I'm having a weird issue with the latest pf_ring that allows user
specified snaplen/caplen to tell pf_ring what the bucket length should
be.  Everything works fine until I restart one of the apps argus which
has a smaller snaplen than snort and daemonlogger both with a snaplen
of 1515.  Once I do this both deamonlogger and snort start to only
capture 96 bytes of traffic that is specified as the argus snaplen.
If I change the argus snaplen to to 1515 everything is fine, but I
don't want to do that as the boxes are overtaxed as it is, and I need
to roll the argus files via cron daily....

Regards,

Will
_______________________________________________
Ntop-dev mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-dev

Reply via email to