Hi all,
we are experiencing high CPU usage on one of Astaro firewall where IPS functionality is enabled. Snort almost consumes 98% of the CPU. During such time, we could see only one snort instance used to run and could not find name of the signature which causing high CPU usage. To solve this problem, we had to reboot the Astaro device. Would like to know why snort uses more CPU usage or in which situation snort can consume more CPU usage
Is there any way to find out which signature consumes more CPU in snort during high CPU usage time?
Due to this high CPU usage, we are not enabling IPS funtionality in all our Astaro firewalls. So your update on this will help us to isolate or optimize our IPS rules.
Regards
Papdheen
This thread was automatically locked due to age.