# High orig\_bytes value

**URL:** https://community.zeek.org/t/high-orig-bytes-value/4315
**Category:** Zeek
**Created:** [August 29, 2016, 5:01pm UTC](https://community.zeek.org/t/high-orig-bytes-value/4315 "2016-08-29T17:01:17Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Danilo\_Nicolo](https://avatars.discourse-cdn.com/v4/letter/d/5f8ce5/32.png) [@Danilo\_Nicolo](https://community.zeek.org/u/Danilo_Nicolo)
#### Post date: [August 29, 2016, 5:01pm UTC](https://community.zeek.org/t/high-orig-bytes-value/4315/1 "2016-08-29T17:01:17Z")

</div>

Hello guys,

I’m testing Bro 2.5 beta with netmap, and I noticed this row:

{“ts”:1472467151.681244,“uid”:“CgoIaB3GxSCIEgWea7”,“id.orig\_h”:“192.168.181.107”,“id.orig\_p”:11328,“id.resp\_h”:“172.16.1.60”,“id.resp\_p”:9997,“proto”:“tcp”,“duration”:0.362595,“orig\_bytes”:4294967296,“resp\_bytes”:4294967296,“conn\_state”:“SF”,“local\_resp”:true,“missed\_bytes”:1168863602,“history”:“ShAFFff”,“orig\_pkts”:7,“orig\_ip\_bytes”:292,“resp\_pkts”:4,“resp\_ip\_bytes”:184,“tunnel\_parents”:[],“local\_origi”:“T4”,“local\_respo”:“T4”}

If you look at this log, you can see that there was 4gb data exchanged in 0sec, that’s impossible.  
I followed the netmap installation guide by patching the igb intel driver and so using libpcap system (version 0.8)

Anyone has had this kind of problem? Might it be a netmap problem? Should I use pf\_ring instead?

Thanks in advance,  
Danilo

---

<div class="post-metadata">

### Author: ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)
#### Post date: [September 7, 2016, 7:43pm UTC](https://community.zeek.org/t/high-orig-bytes-value/4315/2 "2016-09-07T19:43:04Z")

</div>

Unfortunately you haven't given enough information to debug this problem. I haven't heard of a problem like this with netmap.

Although, I can say that it would possible to cause a Bro log to look like that if two systems on the network were out to mess with you. Those large numbers are calculated by doing tcp sequence ID tracking. If you look at the orig\_ip\_bytes and resp\_ip\_bytes fields, you can see those are much smaller because they are actually calculated from the byte size of packets seen.

Are you seeing this regularly, or was this a one-off? Are you running packet-bricks or lb on top of netmap or do you have Bro connecting to a netmap interface directly? Are you using the netmap libpcap wrappers or are you using the netmap plugin?

.Seth

---

<div class="post-metadata">

### Author: ![Danilo\_Nicolo](https://avatars.discourse-cdn.com/v4/letter/d/5f8ce5/32.png) [@Danilo\_Nicolo](https://community.zeek.org/u/Danilo_Nicolo)
#### Post date: [September 8, 2016, 8:57am UTC](https://community.zeek.org/t/high-orig-bytes-value/4315/3 "2016-09-08T08:57:05Z")

</div>

Hello,

Sorry for short information.

I’m using Packet-bricks + Bro (2.5) + Netmap (plugin)

Yesterday I removed Packet-bricks from the chain and the problem was solved.

So in some way packet-bricks will cause that problem in my network (regurarly).

I was using git version of packet-bricks in this way:

Eth0 --\

Eth1 ------ Merge → Slot → LoadBalance ----- Slot → Bro worker #1

Eth2 —/ — Slot → Bro worker #2

Eth3 --/

Should I take the orig\_ip\_bytes instead of orig\_bytes to have more reliability?

Thanks for your suggestions

---

<div class="post-metadata">

### Author: ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)
#### Post date: [September 8, 2016, 1:49pm UTC](https://community.zeek.org/t/high-orig-bytes-value/4315/4 "2016-09-08T13:49:23Z")

</div>

> Sorry for short information.  
> I’m using Packet-bricks + Bro (2.5) + Netmap (plugin)

Thanks for the explanation of what you're doing, that's helpful.

> Yesterday I removed Packet-bricks from the chain and the problem was solved.

That's good to know.

> Eth0 --\
> 
> Eth1 ------ Merge -\> Slot -\> LoadBalance ----- Slot -\> Bro worker #1
> 
> Eth2 ---/ \--- Slot -\> Bro worker #2
> 
> Eth3 --/

Have you tried just sniffing a single interface and doing load balancing? Could you send the script you're running in packet-bricks?

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

### Author: ![Danilo\_Nicolo](https://avatars.discourse-cdn.com/v4/letter/d/5f8ce5/32.png) [@Danilo\_Nicolo](https://community.zeek.org/u/Danilo_Nicolo)
#### Post date: [September 9, 2016, 3:48pm UTC](https://community.zeek.org/t/high-orig-bytes-value/4315/5 "2016-09-09T15:48:21Z")

</div>

Hello Seth,

> > Have you tried just sniffing a single interface and doing load balancing? Could you send the script you’re running in packet-bricks?

No, I’ve tried to sniff four interfaces, merging them to one and load-balancing on two worker (for now).

I used first:

Brick.new(“Merge”)

And then:

Brick.new(“LoadBalancer”)

The flow works well as programmed, but sometimes that problem of wrong orig\_bytes happened.

Now I removed packet-bricks layer connecting netmapped-interfaces directly to bro and it’s working well.

Thanks for your interest

Danilo

---

<div class="post-metadata">

### Author: ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)
#### Post date: [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/high-orig-bytes-value/4315/6 "2022-05-06T15:43:58Z")

</div>


