# 10Gbps Bro deployment

**URL:** <https://community.zeek.org/t/10gbps-bro-deployment/4331>\
**Category:** Zeek\
**Created:** [September 11, 2016, 9:03am UTC](https://community.zeek.org/t/10gbps-bro-deployment/4331 "2016-09-11T09:03:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Edwards](https://avatars.discourse-cdn.com/v4/letter/j/e95f7d/32.png) [@John\_Edwards](https://community.zeek.org/u/John_Edwards)\
**Post date:** [September 11, 2016, 9:03am UTC](https://community.zeek.org/t/10gbps-bro-deployment/4331/1 "2016-09-11T09:03:50Z")

</div>

Hi,

I will be deploying an instance of Bro onto two fairly powerful Ubuntu servers that sit off a pair of 10Gbps TAP devices. I have only used Bro on a smaller 1Gbps TAP and just deployed it after compiling the source of 2.4.1 and got the file extraction scripts to work.

What sort of deployment options should i be considering? The reason i ask is out of the box the Bro’s logs seem to be quite light weight in terms of disk usage consumption and they are rotated and gz. I want to put together a deployment document as to how and why i will deploy it.

As the TAPs are passive they don’t aggregate, they collect both RX and TX fiber but in separate steams so i will need to aggregate the data or bond the interfaces. Then is it best i have Bro running on both systems and built another as the Cluster head? to use Broctl? or having two separate instances of bro 1 per Ubuntu server is ok?

The data will be placed back into a large splunk indexer.

Thanks for any assistance.

Cheers,

John

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/10gbps-bro-deployment/4331/2 "2022-05-06T15:44:00Z")

</div>


