Project

General

Profile

Actions

Feature #3293

closed

eve: per thread output files

Added by Andreas Herz almost 2 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Related issues

Related to Task #3288: Suricon 2019 brainstormNewVictor JulienActions
Related to Bug #2726: writing large number of json events on high speed traffic results in packet dropsClosedJason IshActions
Actions #1

Updated by Victor Julien almost 2 years ago

  • Subject changed from Add support to split eve json output to dedicated worker thread files similiar to pcap to eve: per thread output files

To avoid contention on the single output structure (+lock) when having many worker threads, add a mode where we have a eve.json per thread.

Modern tools like logstash/filebeat support tracking & processing multiple files w/o issue.

Actions #2

Updated by Victor Julien almost 2 years ago

  • Parent task deleted (#3288)
Actions #3

Updated by Victor Julien almost 2 years ago

  • Related to Task #3288: Suricon 2019 brainstorm added
Actions #4

Updated by Victor Julien almost 2 years ago

  • Related to Bug #2726: writing large number of json events on high speed traffic results in packet drops added
Actions #5

Updated by Jeff Lucovsky over 1 year ago

Mats Klepsland Will you be able to work on this issue? If not, I'd be happy to pick it up.

Actions #6

Updated by Mats Klepsland over 1 year ago

Jeff Lucovsky wrote:

Mats Klepsland Will you be able to work on this issue? If not, I'd be happy to pick it up.

Hi, Jeff.

My time is stretched both at work and at home, at the moment, so please do if you want to. This is a feature that I think would be awesome to have, performance wise :)

Actions #7

Updated by Victor Julien about 1 year ago

  • Status changed from New to Assigned
  • Assignee changed from Mats Klepsland to Jeff Lucovsky
  • Target version changed from 70 to 6.0.0beta1
Actions #8

Updated by Jeff Lucovsky about 1 year ago

  • Status changed from Assigned to In Review
Actions #9

Updated by Jeff Lucovsky about 1 year ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF