Re: URLscan overhead
From: akomolafe (deji@prontomail.com)Date: 09/26/01
- Previous message: Marc Maiffret: "RE: SecureIIS"
- In reply to: shewitt@cdw.com: "RE: URLscan overhead"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <013e01c146c5$80057ef0$f701fe0a@commtouch.com> From: "akomolafe" <deji@prontomail.com> To: <focus-ms@securityfocus.com> Subject: Re: URLscan overhead Date: Wed, 26 Sep 2001 12:57:41 -0700
"Quite a lot" is around 50K hits a day on a server. We see CPU spikes every
now and then, but nothing to cause concerns. Because of the amount of
processing we do on the servers, no we don't do perf counters. Again, we are
STILL measuring the statistics and URLScan is only running on our 5
"scapegoat" (but live)servers, we haven't fully deployed it.
HTH
----- Original Message -----
From: <shewitt@cdw.com>
To: <deji@prontomail.com>; <focus-ms@securityfocus.com>
Sent: Wednesday, September 26, 2001 10:49 AM
Subject: RE: URLscan overhead
> I'm always concerned when adding software directly to the web servers in
> case it will slow things down. I'm curious about your experiences on your
> network.
>
> What's "quite a lot of traffic"? How much bandwidth are you using? Have
> you seen a hit to the CPU utilization? Do you watch any IIS perfmon
> counters? Such as request execution time, requests / second, current
> connections, etc? I'm curious how this changed after utilizing URLScan.
>
> How does the size of the log compare to that of an IIS traffic log?
>
> --------------------------
> Scott Hewitt
> WEB/WAN Administrator
> CDW Computer Centers, Inc.
> shewitt@cdw.com
>
>
> -----Original Message-----
> From: akomolafe [mailto:deji@prontomail.com]
> Sent: September 26, 2001 10:50 AM
> To: Mark Fagan; Focus-Ms (E-mail)
> Subject: Re: URLscan overhead
>
>
> The log is VERY "chatty" and gets big quite often. We had to move URLScan
to
> a larger partition, so it's not in the inetpub\wwwroot as suggested in the
> readme.
>
> As for overhead, we are still watching it like an eagle. We get quite a
lot
> of traffic, but we haven't noticed an extra-ordinary performance hit YET.
>
> HTH
>
>
> ----- Original Message -----
> From: "Mark Fagan" <Mark.Fagan@esat.com>
> To: "Focus-Ms (E-mail)" <focus-ms@securityfocus.com>
> Sent: Wednesday, September 26, 2001 4:45 AM
> Subject: URLscan overhead
>
>
> > Anyone any ideas on increased load on servers implementing urlscan.
> >
> >
> > **********************************************************************
> > This email and any files transmitted with it are confidential and
> > intended solely for the use of the individual or entity to whom they
> > are addressed. If you have received this email in error please notify
> > the system manager.
> >
> > http://www.esatbusiness.com
> >
> > **********************************************************************
- Previous message: Marc Maiffret: "RE: SecureIIS"
- In reply to: shewitt@cdw.com: "RE: URLscan overhead"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]