# zeek worker nodes

**URL:** <https://community.zeek.org/t/zeek-worker-nodes/5894>\
**Category:** Zeek\
**Created:** [November 6, 2019, 12:09pm UTC](https://community.zeek.org/t/zeek-worker-nodes/5894 "2019-11-06T12:09:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![venkatesh\_bandari](https://avatars.discourse-cdn.com/v4/letter/v/a9a28c/32.png) [@venkatesh\_bandari](https://community.zeek.org/u/venkatesh_bandari)\
**Post date:** [November 6, 2019, 12:09pm UTC](https://community.zeek.org/t/zeek-worker-nodes/5894/1 "2019-11-06T12:09:33Z")

</div>

Hello Team,

could you please share the details if anyone of you deployed worker nodes .a little background of what iam doing  
1.installed zeek  
2.we are seeing 40% packet loss on interface  
3.installed pf\_ring but i was not able to do the below step as i already installed zeek(not compiled from source).It is a yum install  
ldd /usr/local/bro/bin/bro | grep pcap libpcap.so.1 =\> /opt/pfring/lib/libpcap.so.1

4.i went a ahead and spawn 2 worker nodes  
[worker-1]  
type=worker  
host=localhost  
interface=eth0  
lb\_method=pf\_ring  
lb\_procs=10  
pin\_cpus=2,3,4,5,6,7,8,9,10,11

[worker-2]  
type=worker  
host=localhost  
interface=eth0  
lb\_method=pf\_ring  
lb\_procs=10  
pin\_cpus=12,13,14,15,16,17,18,19,20,21

---

<div class="post-metadata">

**Author:** ![venkatesh\_bandari](https://avatars.discourse-cdn.com/v4/letter/v/a9a28c/32.png) [@venkatesh\_bandari](https://community.zeek.org/u/venkatesh_bandari)\
**Post date:** [November 6, 2019, 12:10pm UTC](https://community.zeek.org/t/zeek-worker-nodes/5894/2 "2019-11-06T12:10:55Z")

</div>

Hello Team,

could you please share the details if anyone of you deployed worker nodes .a little background of what iam doing  
1.installed zeek  
2.we are seeing 40% packet loss on interface  
3.installed pf\_ring but i was not able to do the below step as i already installed zeek(not compiled from source).It is a yum install  
ldd /usr/local/bro/bin/bro | grep pcap libpcap.so.1 =\> /opt/pfring/lib/libpcap.so.1

4.i went a ahead and spawn 2 worker nodes  
[worker-1]  
type=worker  
host=localhost  
interface=eth0  
lb\_method=pf\_ring  
lb\_procs=10  
pin\_cpus=2,3,4,5,6,7,8,9,10,11

[worker-2]  
type=worker  
host=localhost  
interface=eth0  
lb\_method=pf\_ring  
lb\_procs=10  
pin\_cpus=12,13,14,15,16,17,18,19,20,21

5.iam still seeing packet drops after spinning 2 worker nodes

my question is did any one implement worker nodes and saw any improvements

any help is much appreciated

thanks  
Venkatesh

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/zeek-worker-nodes/5894/3 "2022-05-06T15:46:51Z")

</div>


