Thought I’d write in to seek some guidance from the list.
I’ve got bro running on RHEL 6.5 sitting on a box with 20 cores and 64 GB of RAM and a RAID 6 configuration through 1.2TB disks on a LSI raid card. This is a Cisco UCS 1u server.
I’m running with myricom’s sniffer 10G software (v3) in an x16 slot set at GEN II in the BIOS (I don’t have a x8 slot to put it in).
I’ve tried running both bro out of git and bro 2.3.
/usr/local/bro/etc/node.conf looks like:
drop ring full