Re: cluster configuration hot update
Jon Siwek <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAMzgZ0LTs32wW8N90E9pXtGGcWHREbi_kxSFtA42UK7Gx=7ApA@mail.gmail.com> |
On Fri, May 3, 2019 at 1:01 AM Palumbo Mauro <[email protected]> wrote: > As far as I understand, I can update the node.cfg file, for example with new workers, and run the deploy command in broctl to update the configuration. But this will stop and restart the workers for a short time. Is there a way to avoid it? I had a look into the cluster framework and other parts of zeek’s code, but it doesn’t seem so easy to me. A dynamically changing cluster is theoretically possible, but not something I know any tricks to get working now -- it's likely some effort to hack that feature in or else try to roll your own cluster config that uses the underlying Broker framework to set up connections instead of the default cluster/broctl frameworks. - Jon _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek