# Bro Cluster Help

**URL:** <https://community.zeek.org/t/bro-cluster-help/1634>\
**Category:** Zeek\
**Created:** [June 4, 2010, 9:48pm UTC](https://community.zeek.org/t/bro-cluster-help/1634 "2010-06-04T21:48:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sam\_Oehlert](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@Sam\_Oehlert](https://community.zeek.org/u/Sam_Oehlert)\
**Post date:** [June 4, 2010, 9:48pm UTC](https://community.zeek.org/t/bro-cluster-help/1634/1 "2010-06-04T21:48:55Z")

</div>

I am attempting to figure out how to get a Bro Cluster up and running, but all documentation I see is outdated. I am trying to use the latest SVN (though if you know how to do it with 1.5, I'll figure out the differences between the two), and I am having problems.

First of all, I have the manager and proxy nodes as the main box, with two workers being in virtualized OSes. They can all ping each other, so I know they are connected. I do not know how to start up bro in this method though. Should I be starting bro on the workers, then broctl on the manager? Vice Versa? Only start broctl?

My other problem is a new one, I am now getting an error when I try to start broctl on the manager node. It keeps telling me that the broctl start script can only be run on a manager node, is there some place to tell it this is the manager (it was working before, the errors I got were related to the workers, not the manager).

Sorry for the long email, but I have been working for quite a while and I can't figure this out. I have also spent a long time searching for help that's out there already, sorry if I missed it.

Thank you.  
Sam

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [June 7, 2010, 5:37pm UTC](https://community.zeek.org/t/bro-cluster-help/1634/2 "2010-06-07T17:37:42Z")

</div>

> I am attempting to figure out how to get a Bro Cluster up and  
> running, but all documentation I see is outdated.

The README.html coming with the distribution in aux/broctl is  
current:

&nbsp;&nbsp;&nbsp;&nbsp;[http://svn.icir.org/bro/trunk/bro/aux/broctl/README.html](http://svn.icir.org/bro/trunk/bro/aux/broctl/README.html)  
&nbsp;&nbsp;&nbsp;&nbsp;

> First of all, I have the manager and proxy nodes as the main box,  
> with two workers being in virtualized OSes. They can all ping each  
> other, so I know they are connected. I do not know how to start up  
> bro in this method though. Should I be starting bro on the workers,  
> then broctl on the manager? Vice Versa? Only start broctl?

I haven't tried such a setup yet but generally it shouldn't make a  
difference whether the workers are in VMs or not. Use broctl (only)  
on the manager, per the README.

> broctl start script can only be run on a manager node, is there some  
> place to tell it this is the manager (it was working before, the  
> errors I got were related to the workers, not the manager).

Depending on the version you're using, this patch might or might not  
be applied:

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[http://tracker.icir.org/bro/attachment/ticket/190/is-local-manager.patch.txt](http://tracker.icir.org/bro/attachment/ticket/190/is-local-manager.patch.txt)

If it is already applied, please delete spool/debug.log, run the  
start command again, and then send me the new spool/debug.log.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:39pm UTC](https://community.zeek.org/t/bro-cluster-help/1634/3 "2022-05-06T15:39:07Z")

</div>


