[logs] Fwanalog/analog performance guidelines?

From: Clark, Bill W. (Bill.Clark@private)
Date: Wed Mar 03 2004 - 13:19:41 PST

  • Next message: Jason Haar: "Re: [logs] Fwanalog/analog performance guidelines?"

    Anybody have any recommendations on how to speed up fwanalog or analog?
    I haven't figured out which one is or if both are just naturally slow
    because of the algorithms used in regex.  I am attempting to analyze the
    month fwdump from the Honeynet project and it has been running for about
    3 hours with no end in sight.  I have even tried renice the process to
    give them highest priority on my wkstn but to no avail.  It looks like
    the CPU is hardly even working and memory isn't taxed.  Just looking for
    rules of thumb as to how long fwanalog/analog take to run generally and
    if there are any steps that improve the timeline.
    
    Thanks,
    
    Bill W. Clark
    Sr. Security Engineer, Data Security
    bill.clarkATumbDOTcom
    UMB Bank | http://www.umb.com
    
    PGP ID: 0x7E1F8D94
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysis@private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Wed Mar 03 2004 - 13:29:00 PST