Are there any performance benefits over compiling Bro with pf_ring (–with-pcap=*) versus using the Bro pf_ring plugin?
Additionally, if I’m using the ZC drivers (with zbalance_ipc clusters) is the plugin compatible or do I still need to compile Bro with the —with-pcap option?
Also, this documentation is a tad outdated at this point:
https://www.bro.org/sphinx-git/configuration/index.html
Thanks!
-Dave