# New Cluster configuration

**URL:** <https://community.zeek.org/t/new-cluster-configuration/4380>\
**Category:** Zeek\
**Created:** [September 30, 2016, 7:56am UTC](https://community.zeek.org/t/new-cluster-configuration/4380 "2016-09-30T07:56:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Edwards](https://avatars.discourse-cdn.com/v4/letter/j/e95f7d/32.png) [@John\_Edwards](https://community.zeek.org/u/John_Edwards)\
**Post date:** [September 30, 2016, 7:56am UTC](https://community.zeek.org/t/new-cluster-configuration/4380/1 "2016-09-30T07:56:12Z")

</div>

Hi everyone

Today successfully installed Bro as a standalone worker on an ubuntu system, it has 16cores, 8GB ram (can be expanded) and about 2TB of disk. Its receiving traffic from a passive fibre network interface.

The interface configuration is as follows

br0 - bridged interface

p1p1 - RX of fibre

p1p2 - TX of fibre

br1 - Bridged interface

p2p1 - RX of fibre

p2p2 - TX of fibre

So i have br0 configured and being monitored correctly. br0 is monitoring one part of the network up towards public facing infrastructure and br1 is monitoring more local stuff so its not NAT’d and closer to the hosts.

As it is one physical system with 2 interfaces what is the best way for my to monitor both feeds and log it correctly. All of my logs are being fed into a SIEM with JSON output.

Can i have separate roles configured on the one physical system and each interface being defined as a separate worker?

So PF\_RING as the front end, then a manager and proxy but each worker defined within the Cluster worker config as the same host but different interfaces.

Or should i suggest getting additional hardware and splitting the interfaces? it seems a little silly that one worker can only monitor one interface i thought. thats why i thought id ask here first.

Thanks,

John

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [October 5, 2016, 12:25pm UTC](https://community.zeek.org/t/new-cluster-configuration/4380/2 "2016-10-05T12:25:02Z")

</div>

You should be able to do what you're attempting to do on a single system. You could configure multiple workers, each sniffing a bridge interface and load balancing.

Probably something like this, but with an appropriate number of processes for your system....

[worker-1]  
host=localhost  
type=worker  
interface=br0  
lb\_method=pf\_ring  
lb\_procs=4

[worker-2]  
host=localhost  
type=worker  
interface=br1  
lb\_method=pf\_ring  
lb\_procs=4

Your logs will be a bit repetitive though since it sounds like you're monitoring inside and outside of a NATing router.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Michal\_Purzynski1](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Michal\_Purzynski1](https://community.zeek.org/u/Michal_Purzynski1)\
**Post date:** [October 5, 2016, 8:34pm UTC](https://community.zeek.org/t/new-cluster-configuration/4380/3 "2016-10-05T20:34:57Z")

</div>

Also, use a modern kernel and afpacket rather then pfring.

---

<div class="post-metadata">

**Author:** ![M\_P](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@M\_P](https://community.zeek.org/u/M_P)\
**Post date:** [October 6, 2016, 2:49pm UTC](https://community.zeek.org/t/new-cluster-configuration/4380/4 "2016-10-06T14:49:31Z")

</div>

Hello Michal,

Would you mind elaborating more, please? I am not trying to hijack the thread but more interested in the suggestion. Any pointers are welcome.

MP.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/new-cluster-configuration/4380/5 "2022-05-06T15:44:05Z")

</div>


