I am making some new monitoring systems based mostly on Bro, and my company has purchased 10G Endace cards to make things pretty awesome. That said, I am finding some indications that Bro can support the Endace card API directly if you compile with “–with-DAG=/path/to/dagtool/installation” but this seemed to be experimental long ago, and rumors circulated of it being dropped at some point. I can’t seem to find any indication in the official docs about retained or dropped support native Endace card support. The official changelog only cites the introduction of experimental support long ago.
Can I have confirmation that this is still supported? Is stable? Is going to be retained as far as anyone knows? I am using Bro 2.3.x on RHEL x64.
Brad Miller | Comerica Bank
Information Security Architecture
Office: 248.371.4249 | Mobile: 920.378.8138