# Zeek + PF\_Ring Issue

**URL:** <https://community.zeek.org/t/zeek-pf-ring-issue/5945>\
**Category:** Zeek\
**Created:** [December 18, 2019, 10:29am UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945 "2019-12-18T10:29:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jorge\_Garcia\_Rodrig1](https://avatars.discourse-cdn.com/v4/letter/j/90db22/32.png) [@Jorge\_Garcia\_Rodrig1](https://community.zeek.org/u/Jorge_Garcia_Rodrig1)\
**Post date:** [December 18, 2019, 10:29am UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/1 "2019-12-18T10:29:33Z")

</div>

Hi Zeekers!

I need to resolve a problem attached to Zeek when its configured to work with PF\_Ring.

The thing is that we receive between 1.0 and 2.5 GB/s in a fiber interface. Also when we lauch the command “Zeekctl top” to check the Cpu usage and the traffic managed in each worker, we see that the sum of the traffic of all workers is greater than the traffic we receive through the interface.

This makes me think that we have something badly configured in PF\_Ring or somehow Zeek is generating some kind of loop.

For example, receiving 2Gb/s, i execute “Zeekctl top” and the result is the next one:

Name Type Host Pid VSize Rss Cpu Cmd

logger logger localhost 11474 3G 118M 50% zeek

manager manager localhost 11520 589M 98M 25% zeek

proxy-1 proxy localhost 11565 610M 113M 18% zeek

worker-1-1 worker localhost 11693 1G 570M 62% zeek

worker-1-2 worker localhost 11701 1G 574M 62% zeek

worker-1-3 worker localhost 11711 1G 573M 68% zeek

worker-1-4 worker localhost 11713 1G 572M 50% zeek

worker-1-5 worker localhost 11718 3G 2G 106% zeek

worker-1-6 worker localhost 11719 1G 567M 62% zeek

worker-1-7 worker localhost 11726 1G 579M 68% zeek

worker-1-8 worker localhost 11732 1G 575M 56% zeek

worker-1-9 worker localhost 11733 1G 571M 68% zeek

worker-1-10 worker localhost 11735 1G 558M 62% zeek

Hope someone of you can help me to resolve this.

Really thank you.

Best Regards!

---

<div class="post-metadata">

**Author:** ![Phil\_Rzewski](https://avatars.discourse-cdn.com/v4/letter/p/bb73d2/32.png) [@Phil\_Rzewski](https://community.zeek.org/u/Phil_Rzewski)\
**Post date:** [December 18, 2019, 3:13pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/2 "2019-12-18T15:13:24Z")

</div>

Jorge,

Have you checked for duplicate events in Zeek? I recall when I set up Zeek with PF\_RING, I followed the instructions at [https://www.zeek.org/documentation/load-balancing.html](https://www.zeek.org/documentation/load-balancing.html) and only followed the instructions through the “Using PF\_RING” paragraph. In my case I was pinning to four CPUs, and what I found was that I was getting four copies of the all sniffed network traffic onto my Zeek environment, one going to each worker. The symptom that tipped me off is that I would see was four “conn” events for a given connection, each with all the same source/dest/byte counts/etc. but each had a different UID. I suspect that if I continued on to additional paragraphs I would have been able to get past this problem (note how in the paragraph “Using PF\_RING+DNA with symmetric RSS” it says “You can sniff each packet only once”… don’t we always want that? 🙂 ) Alas, I’m not 100% sure of the solution as I started using a different Zeek approach instead. Hope it helps though.

---

<div class="post-metadata">

**Author:** ![Darren\_S](https://avatars.discourse-cdn.com/v4/letter/d/59ef9b/32.png) [@Darren\_S](https://community.zeek.org/u/Darren_S)\
**Post date:** [December 18, 2019, 9:17pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/3 "2019-12-18T21:17:32Z")

</div>

I'm not certain if it's the exact root cause, but does the advice on  
PCAP\_PF\_RING\_CLUSTER\_ID at  
[https://www.ntop.org/guides/pf\_ring/thirdparty/bro.html](https://www.ntop.org/guides/pf_ring/thirdparty/bro.html) apply?

> ...Bro needs to setup a pf\_ring kernel cluster in order to split the traffic across the processes (otherwise your get duplicated data).

- Darren

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [December 18, 2019, 9:29pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/4 "2019-12-18T21:29:37Z")

</div>

Can you run bro-doctor: [https://packages.bro.org/packages/view/1251f948-f435-11e9-9321-0a645a3f3086](https://packages.bro.org/packages/view/1251f948-f435-11e9-9321-0a645a3f3086) (works with zeek, just didn’t change the name). that will likely tell you what is wrong. You’re probably not actually using pf\_ring and should use the native plugin and not the pcap wrapper.

---

<div class="post-metadata">

**Author:** ![Jorge\_Garcia\_Rodrig1](https://avatars.discourse-cdn.com/v4/letter/j/90db22/32.png) [@Jorge\_Garcia\_Rodrig1](https://community.zeek.org/u/Jorge_Garcia_Rodrig1)\
**Post date:** [December 19, 2019, 12:16pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/5 "2019-12-19T12:16:24Z")

</div>

I have ran bro-doctor as you said and certainly I saw interesting things, for example:

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [December 19, 2019, 3:06pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/6 "2019-12-19T15:06:47Z")

</div>

> I have ran bro-doctor as you said and certainly I saw interesting things, for example:
> 
> ###################################################################
> 
> # Checking if connections are unevenly distributed across workers
> 
> ###################################################################
> 
> error: The distribution of connections across workers seems uneven:
> 
> worker-1-5: 462 connections
> 
> worker-1-4: 890 connections
> 
> worker-1-7: 874 connections
> 
> worker-1-6: 4122 connections
> 
> worker-1-1: 432 connections
> 
> worker-1-3: 930 connections
> 
> worker-1-2: 907 connections
> 
> worker-1-9: 451 connections
> 
> worker-1-8: 435 connections
> 
> worker-1-10: 497 connections

Interesting indeed. If you look at your conn log can you tell anything about all those connections that worker-1-6 is seeing?

> Let me know what do you think about the report.
> 
> I have checked about the PF\_Ring plugin but it gives me an error, im not sure if im following the last update of this plugin.  
> [https://github.com/ntop/bro-pf\_ring](https://github.com/ntop/bro-pf_ring)

you should be able to zkg install bro-pf\_ring.. or install it manually with ./configure && make && sudo make install. are you getting an error when you do that?

> Also doing a further investigation it seems that the script that is overcharguing the cpu is the weird.zeek ¿Is there a way to disable this script?

Do you say that because you have a lot of entries in the weird log? that points to traffic issues that need to be fixed… disabling the weird logs will just ignore the problem. What are the top weirds that you are seeing?

cat /usr/local/zeek/logs/current/weird.log |zeek-cut name|sort|uniq -c|sort -rn

What did you see as the result from this check?

# Checking if many recent connections have a SAD or had history

---

<div class="post-metadata">

**Author:** ![Jorge\_Garcia\_Rodrig1](https://avatars.discourse-cdn.com/v4/letter/j/90db22/32.png) [@Jorge\_Garcia\_Rodrig1](https://community.zeek.org/u/Jorge_Garcia_Rodrig1)\
**Post date:** [December 19, 2019, 3:55pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/7 "2019-12-19T15:55:47Z")

</div>

Enviado desde Outlook\<[http://aka.ms/weboutlook](http://aka.ms/weboutlook)\>

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/zeek-pf-ring-issue/5945/8 "2022-05-06T15:46:57Z")

</div>


