# multiple workers per cluster node

**URL:** <https://community.zeek.org/t/multiple-workers-per-cluster-node/1827>\
**Category:** Zeek\
**Created:** [March 4, 2011, 10:29pm UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827 "2011-03-04T22:29:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dop](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@Dop](https://community.zeek.org/u/Dop)\
**Post date:** [March 4, 2011, 10:29pm UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/1 "2011-03-04T22:29:40Z")

</div>

Hopefully quick question. How would you go about configuring Bro cluster  
nodes to each run dual clients (one per input interface)?

Ie, all of my systems have input sources on eth4 and eth5. Instead of  
bonding those together and running a single Bro thread on bond0, I'd  
rather have two. Something is getting super confused when I try to do it:

For each worker I have this:  
[nids-21a]  
type=worker  
host=10.142.148.21  
interface=eth4

[nids-21b]  
type=worker  
host=10.142.148.21  
interface=eth5

[BroControl] \> start  
starting manager ...  
starting proxy-1 ...  
starting nids-21a ...  
starting nids-21b ...  
starting nids-22a ...  
starting nids-22b ...  
starting nids-23a ...  
starting nids-23b ...  
starting nids-24a ...  
starting nids-24b ...  
(nids-22a still initializing)  
(nids-21b still initializing)  
(nids-23b still initializing)  
(nids-21a still initializing)

What's strange is that it seems to fail unevenly. Fails totally on 21,  
partially on 22 and 23, but works on 24. It's always the same nodes  
failing.

Thanks,  
-Dop

---

<div class="post-metadata">

**Author:** ![William\_Jones](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@William\_Jones](https://community.zeek.org/u/William_Jones)\
**Post date:** [March 4, 2011, 11:52pm UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/2 "2011-03-04T23:52:23Z")

</div>

Instead of

For each worker I have this:  
[nids-21a]  
type=worker  
host=10.142.148.21  
interface=eth4

[nids-21b]  
type=worker  
host=10.142.148.21  
interface=eth5

Try:

For each worker I have this:  
[nids-21]  
type=worker  
host=10.142.148.21  
interface=eth4 -Ieth5

If you node had motile nodes you can write a pcap filter to split the ip space into multiples of 2,4 or 8 and run 2, 4, or 8 instance on the node.

This set up allow one bro instance to see by sides of the same flow and will allow you to take advanced of all the cpu on a node.

Bill Jones

---

<div class="post-metadata">

**Author:** ![Justin\_Azoff](https://avatars.discourse-cdn.com/v4/letter/j/eb9ed0/32.png) [@Justin\_Azoff](https://community.zeek.org/u/Justin_Azoff)\
**Post date:** [March 5, 2011, 12:50am UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/3 "2011-03-05T00:50:23Z")

</div>

This should work fine, I run 4 workers on one machine without any  
issues.

It sounds like maybe you have some filesystem issues preventing bro from  
starting.

What do you have in /usr/local/bro/spool/ for each of the failing nodes?  
Is there anything in the stdout or stderr logs?

/usr/local/bro/spool/debug.log may also have useful info

I would focus on the machine that it starts partially on.

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [March 5, 2011, 1:27am UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/4 "2011-03-05T01:27:26Z")

</div>

Do you get a crash message when a worker fails?

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Dop](https://avatars.discourse-cdn.com/v4/letter/d/97f17d/32.png) [@Dop](https://community.zeek.org/u/Dop)\
**Post date:** [March 5, 2011, 4:50am UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/5 "2011-03-05T04:50:50Z")

</div>

Thanks everyone for the replies and suggestions. Apparently I just forgot  
to run 'install' after changing the node config which is embarrassing, but  
I still find it interesting that they all reacted differently.

For future reference, all of the instances that fail show:

/usr/local/bro/share/bro/broctl/cluster-worker.remote.bro, line 14  
(BroCtl::workers[WORKER]): run-time error, no such index  
/usr/local/bro/share/bro/broctl/cluster-worker.remote.bro, line 13  
($host=BroCtl::manager$ip, $p=BroCtl::manager$p,  
$events=Remote::manager\_events, $connect=T, $sync=F, $retry=1.0 min,  
$class=BroCtl::workers[WORKER]$tag): run-time error, uninitialized list  
value  
/usr/local/bro/share/broctl/scripts/run-bro: line 73: 27140 Segmentation  
fault (core dumped) nohup $tmpbro $@

-Dop

---

<div class="post-metadata">

**Author:** ![William\_Jones](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@William\_Jones](https://community.zeek.org/u/William_Jones)\
**Post date:** [March 5, 2011, 6:16am UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/6 "2011-03-05T06:16:16Z")

</div>

Try name the works

[worker-1]

[worker-2]

...

Bill Jones

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:39pm UTC](https://community.zeek.org/t/multiple-workers-per-cluster-node/1827/7 "2022-05-06T15:39:28Z")

</div>


