# Distributed deployment high cpu low network traffic

**URL:** <https://community.zeek.org/t/distributed-deployment-high-cpu-low-network-traffic/4240>\
**Category:** Zeek\
**Created:** [July 13, 2016, 6:00pm UTC](https://community.zeek.org/t/distributed-deployment-high-cpu-low-network-traffic/4240 "2016-07-13T18:00:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Obdnanr\_smith](https://avatars.discourse-cdn.com/v4/letter/o/9e8a1a/32.png) [@Obdnanr\_smith](https://community.zeek.org/u/Obdnanr_smith)\
**Post date:** [July 13, 2016, 6:00pm UTC](https://community.zeek.org/t/distributed-deployment-high-cpu-low-network-traffic/4240/1 "2016-07-13T18:00:33Z")

</div>

We’re getting around 30-160 mbps worth of traffic on our sensor and when we use multiple workers they are all pegged 96% to 99% cpu utilization. I’ve tried disabling our custom scripts and that wasn’t the culprit. I’ve tried 4 workers and 8 workers, I’ve tried pinning them to different CPUs and nothing has changed anything. We’re using PF\_RING. Any idea how I can trouble shoot this issue? We’re having packet loss, but with the low speed of traffic I wouldn’t expect to see any loss.

PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND  
32027 root 20 0 1527600 1.430g 11696 R 99.9 4.7 10:37.82 bro  
32018 root 20 0 1520192 1.423g 11792 R 99.6 4.6 10:38.83 bro  
32019 root 20 0 1525308 1.428g 11780 R 99.6 4.7 10:39.06 bro  
32032 root 20 0 1522564 1.425g 11712 R 99.6 4.6 10:39.20 bro  
32002 root 20 0 1571588 1.472g 11716 R 98.9 4.8 10:36.93 bro  
32029 root 20 0 1529472 1.432g 11788 R 98.9 4.7 10:38.50 bro  
32016 root 20 0 1341716 1.252g 11712 R 97.9 4.1 10:33.21 bro  
32006 root 20 0 1422616 1.330g 11712 R 96.0 4.3 10:20.19 bro

Thanks

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [July 13, 2016, 6:08pm UTC](https://community.zeek.org/t/distributed-deployment-high-cpu-low-network-traffic/4240/2 "2016-07-13T18:08:10Z")

</div>

First verify that you are truly using pf\_ring..

$ ldd `which bro`|grep -i pcap  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;libpcap.so.1 =\> /opt/pfring/lib/libpcap.so.1 (0x00007f70757a6000)

If bro is not actually linked against pf\_ring you will end up running 8 workers that are all seeing 100% of the traffic.

While bro is running you should also have a bunch of files in /proc/net/pf\_ring/, one for each worker+nic.

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [July 13, 2016, 8:14pm UTC](https://community.zeek.org/t/distributed-deployment-high-cpu-low-network-traffic/4240/3 "2016-07-13T20:14:57Z")

</div>

try deleting the build/ directory in the bro source tree and then running ./configure again with the right options.

As part of the configure output it will say which pcap it is using. We install pf\_ring into /opt/pfring so we build bro using

&nbsp;&nbsp;&nbsp;&nbsp;--with-pcap=/opt/pfring

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/distributed-deployment-high-cpu-low-network-traffic/4240/4 "2022-05-06T15:43:50Z")

</div>


