Options for running self-compiled Zeek and Suricata (pf_ring) #9219
Replies: 1 comment 2 replies
-
You might be able to make this work, but we don't provide any support for custom compiles of Zeek/Suricata or pf_ring. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hey everyone,
I'm looking to get in to security onion, and I'm wondering what options there are for running my own compiles for Zeek and Suricata, because I intend to use the server to also generate netflow information via nProbe, and use zbalance to distribute copies of the packets to each process, since I can't find information about how pf_ring zero-copy and AFPACKET would coexist on the same host.
If anyone has any ideas I'd appreciate it!
Thanks,
Sam n.
Beta Was this translation helpful? Give feedback.
All reactions