Re: Request for Feedback - Zeek Process Supervision Model
Michał Purzyński <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAJ6bFK3jCQ68WqB+vevk5HxB7s-_+wEztwRXho_rLP7AwbgmMw@mail.gmail.com> |
Thanks a lot for doing this. Those who don't want to replace broctl shall do a triple back salto. No one? I see. I have only one request so far, still reading the proposal. Can we make sure that we support a configuration where in a stable state (after initialization has been done) there is only one worker process per core, without all those run-bro scripts and the like? 1 process per core = timer ticking disabled = trips to kernel and back minimized, no partial cache flushing, no partial TLB flushing and higher performance. On Mon, Mar 18, 2019 at 6:44 PM Jon Siwek <[email protected]> wrote: > I just published some design thoughts related to a major new Zeek > feature that's planned/upcoming: a process supervision model that may > act as an alternative (successor) to BroControl. Find that here: > > https://blog.zeek.org/2019/03/beyond-brocontrol-new-process.html > > Feel free to use this mailing list / thread to provide feedback, thanks. > > - Jon > _______________________________________________ > Zeek mailing list > [email protected] > http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek > _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek