Mailing List Archive

Re: question about pf_ring capturing packets
Tasks: 850 total, 15 running, 835 sleeping, 0 stopped, 0 zombie
Cpu(s): 30.6%us, 10.4%sy, 0.0%ni, 52.3%id, 3.1%wa, 0.0%hi, 3.6%si, 0.0%st
Mem: 64532524k total, 24155436k used, 40377088k free, 41924k buffers
Swap: 33119992k total, 16712k used, 33103280k free, 36040096k cached


PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
48912 root 20 0 98232 9892 7680 S 31.6 0.0 850:24.33 dumpcap
48438 root 20 0 98232 9900 7684 S 18.6 0.0 569:46.42 dumpcap
48320 root 20 0 98232 9896 7680 S 16.7 0.0 602:02.61 dumpcap
48794 root 20 0 98232 9900 7684 S 16.7 0.0 1129:06 dumpcap
49030 root 20 0 98232 9900 7684 S 13.0 0.0 969:25.81 dumpcap
48674 root 20 0 98232 9892 7680 S 11.2 0.0 636:08.82 dumpcap
49148 root 20 0 98232 9896 7684 S 11.2 0.0 948:37.75 dumpcap
48556 root 20 0 98232 9896 7680 S 9.3 0.0 847:30.50 dumpcap
49510 root 20 0 98232 9896 7684 S 7.4 0.0 345:45.97 dumpcap
50104 root 20 0 98232 9900 7684 S 7.4 0.0 627:57.76 dumpcap
49274 root 20 0 98232 9892 7680 S 5.6 0.0 450:08.66 dumpcap
49746 root 20 0 98232 9896 7680 S 5.6 0.0 498:28.73 dumpcap
49866 root 20 0 98232 9896 7680 S 5.6 0.0 459:10.20 dumpcap
49986 root 20 0 98232 9896 7680 S 5.6 0.0 524:06.26 dumpcap
50231 root 20 0 98232 9896 7680 S 5.6 0.0 576:57.25 dumpcap
50349 root 20 0 98232 9896 7680 S 5.6 0.0 352:36.55 dumpcap
50585 root 20 0 98232 9892 7680 S 5.6 0.0 379:15.74 dumpcap
49392 root 20 0 98232 9896 7680 S 3.7 0.0 394:47.90 dumpcap
49628 root 20 0 98232 9896 7684 S 3.7 0.0 598:39.03 dumpcap
50467 root 20 0 98232 9900 7684 S 3.7 0.0 507:25.89 dumpcap



Message: 1
Date: Fri, 29 Apr 2016 17:27:15 +0200
From: Alfredo Cardigliano <cardigliano@ntop.org>
To: ntop-misc@listgateway.unipi.it
Subject: Re: [Ntop-misc] question about pf_ring capturing packets
making the network traffic reduce.
Message-ID: <F493956C-1491-4CB8-B8A9-1A319C1DF65F@ntop.org>
Content-Type: text/plain; charset="iso-8859-1"

Hi
please let us see the output of top (press 1 after starting it) when running all the processes on 8 NICs.

Alfredo

> On 29 Apr 2016, at 11:35, sunday2000 <2314476218@qq.com> wrote:
>
> Hi all,
>
> We are using PF_ring to capture packets with 8 NIC in an redhat linux server, with 20 process for capturing and dumping packets. And PF_ring is in standard mode.
> When we capture NIC one by one, then no packets is lossed, but if we capture all NIC concurrently, then one of the NIC will drop/discard packets and other NICs are working well, while the CPU usage is quite low. The traffic flow speed of the loss packet NIC will reduce from 600Mbps to 300Mbps.
>
> Could you tell why this happen?
>
>
>
> _______________________________________________
> Ntop-misc mailing list
> Ntop-misc@listgateway.unipi.it
> http://listgateway.unipi.it/mailman/listinfo/ntop-misc

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 842 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://listgateway.unipi.it/mailman/private/ntop-misc/attachments/20160429/f4233265/attachment-0001.pgp>

------------------------------

_______________________________________________
Ntop-misc mailing list
Ntop-misc@listgateway.unipi.it
http://listgateway.unipi.it/mailman/listinfo/ntop-misc

End of Ntop-misc Digest, Vol 142, Issue 13
******************************************