Questions Regarding Running Multiple Instances of Snort

安井敦哉 via Snort-users <[email protected]> Tue, 28 Nov 2023 12:38:16 +0900
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAACpDQK0LMNAKQqFG=s_rwrgdFfunbTHVUTRmRm=bAy2rgmz5Q@mail.gmail.com>
Dear Team,

Hello, I hope this message finds you well. I am writing to seek guidance on
a few aspects of deploying Snort in our network.

   1.

   When it comes to running multiple instances of Snort, is there a
   functionality for inter-instance coordination, similar to what is seen in a
   Zeek cluster? My intention is to employ a load balancer to distribute
   network traffic evenly across multiple Snort instances. I am keen to
   understand whether Snort supports any mechanisms or features to facilitate
   this type of traffic management and load distribution.
   2.

   In relation to the above, would running each Snort instance within a
   Docker container be a recommended approach? I am considering this for ease
   of deployment and scalability, but would like to know if there are any best
   practices or considerations I should be aware of, especially in terms of
   performance and security.

I would greatly appreciate any advice or insights you could provide on
these matters. Your expertise will be invaluable in helping us optimize our
network security setup.

Thank you for your time and assistance.

Best regards,

AY

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette