I followed this howto http://ossectools.blogspot.com/2011/09/bro-quickstart-cluster-edition.html however I am finding bro is now reporting 4 of everything so the load balancing isn’t working. How can I verify PF_RING is load balancing or what could I be missing? Is there a better document I should be looking at?
Those directions are outdated. Instead of configuring separate workers you should configure a single worker per interface you are sniffing like this…
That will automatically enable the pf_ring load balancing and start up four processes that the traffic on eth0 is load balanced across.
I updated the post to show the new, shorter config.