<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Barnyard2 high CPU usage]]></title><description><![CDATA[<p dir="auto">Hi guys.<br />
I have setup snort and barnyard2 on 2 interfaces (wan and DMZ) with some parameters coming from some how-tos found on the forum. The alerts feed a snorby database. Until recently, all was working fine but recently, the barnyard2 processes consume most of the CPU time (30-40% each).</p>
<p dir="auto">I have tried the following:</p>
<ul>
<li>Reinstall pfsense from scratch and restore a backup</li>
<li>Run different mysql (I run mariadb but for mist settings it the same as mysql) optimizing scripts to tune some settings (cache, etc).</li>
<li>Clear the SID in the snorby DB</li>
</ul>
<p dir="auto">Still, the processes of barnyard2 use a lot of CPU. I only have a vdsl link and very poor traffic coming from the internet to my web server I host behind pfense.</p>
<p dir="auto">I really don't know how to start troubleshoot this issue..any help will be very appreciated on this :)<br />
Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/80949/barnyard2-high-cpu-usage</link><generator>RSS for Node</generator><lastBuildDate>Fri, 11 Sep 2026 05:19:30 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/80949.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 10 Mar 2015 04:15:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Barnyard2 high CPU usage on Thu, 12 Mar 2015 16:18:39 GMT]]></title><description><![CDATA[<p dir="auto">I have the same feeling as you. I really do not know how barnyard2 perform with several sensors and do some queries/update.<br />
I definitively have to put some monitoring on the mysql/mariadb database to know exactly what's going on a do better things than "drop the database and reinstall snorby" :)</p>
<p dir="auto">Maybe barnyard2 itself should produce some alerting info when it sees that there is an issue with the database.</p>
<p dir="auto">Well, I will start to find some good monitoring solution for mysql and keep you updated.</p>
<p dir="auto">Romain</p>
]]></description><link>https://forum.netgate.com/post/526945</link><guid isPermaLink="true">https://forum.netgate.com/post/526945</guid><dc:creator><![CDATA[romainp]]></dc:creator><pubDate>Thu, 12 Mar 2015 16:18:39 GMT</pubDate></item><item><title><![CDATA[Reply to Barnyard2 high CPU usage on Wed, 11 Mar 2015 22:26:32 GMT]]></title><description><![CDATA[<p dir="auto">I have three Barnyard2 instances writing to a Snorby database.  My example of 30 minutes of high CPU utilization is probably a bit high.  It does get to 75%, but I have not timed it precisely.  I just come back later and check and things have calmed down to normal.  I'm not liking how Barnyard2 1.13 talks to databases at all… :(.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/526758</link><guid isPermaLink="true">https://forum.netgate.com/post/526758</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Wed, 11 Mar 2015 22:26:32 GMT</pubDate></item><item><title><![CDATA[Reply to Barnyard2 high CPU usage on Wed, 11 Mar 2015 02:36:11 GMT]]></title><description><![CDATA[<p dir="auto">Hi,<br />
And thanks for your help.<br />
In fact the CPU load for the 2 barnyard2 process was steady (35% for each so they consume all the CPU).<br />
I have tried to not enable all the signature definition with no luck.. Tried to install mytop (top for mysql) and can't find any issue with the load on mysql.<br />
So, I have decided to drop my snorby database, recreate a new one and reinstall snorby and… TADA!  The load on the CPU rise when the signature definition are updated or when the 2 barnyard2 processes start but after a while (less than 10 mns) all is quieter and seem to stay like this. I will not say victory until several days (and some alerts). I will keep you updated.<br />
Thanks!</p>
]]></description><link>https://forum.netgate.com/post/526557</link><guid isPermaLink="true">https://forum.netgate.com/post/526557</guid><dc:creator><![CDATA[romainp]]></dc:creator><pubDate>Wed, 11 Mar 2015 02:36:11 GMT</pubDate></item><item><title><![CDATA[Reply to Barnyard2 high CPU usage on Tue, 10 Mar 2015 21:16:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/romainp">@<bdi>romainp</bdi></a>:</p>
<blockquote>
<p dir="auto">Hi guys.<br />
I have setup snort and barnyard2 on 2 interfaces (wan and DMZ) with some parameters coming from some how-tos found on the forum. The alerts feed a snorby database. Until recently, all was working fine but recently, the barnyard2 processes consume most of the CPU time (30-40% each).</p>
<p dir="auto">I have tried the following:</p>
<ul>
<li>Reinstall pfsense from scratch and restore a backup</li>
<li>Run different mysql (I run mariadb but for mist settings it the same as mysql) optimizing scripts to tune some settings (cache, etc).</li>
<li>Clear the SID in the snorby DB</li>
</ul>
<p dir="auto">Still, the processes of barnyard2 use a lot of CPU. I only have a vdsl link and very poor traffic coming from the internet to my web server I host behind pfense.</p>
<p dir="auto">I really don't know how to start troubleshoot this issue..any help will be very appreciated on this :)<br />
Thanks!</p>
</blockquote>
<p dir="auto">Is this sustained high usage?  By that I mean after say an hour does it back off?  Barnyard2 does this weird business as of the last Barnyard update from upstream where it reads the <em>sid-msg.map</em> file and tries to repopulate/update the signature references table in the MySQL database.  This happens with every Barnyard2 startup, so after each rules update or anytime you make a change in the config, Barnyard2 is restarted and this process kicks off.  On my firewall, it runs the CPU utilization to about 75% for around 30 minutes after Barnyard2 startup.  After about 30 minutes things settle down to normal for me.</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/526508</link><guid isPermaLink="true">https://forum.netgate.com/post/526508</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Tue, 10 Mar 2015 21:16:13 GMT</pubDate></item></channel></rss>