On 2/7/2014 7:49 AM, Torge Husfeldt wrote:
Hi list,
I hope I triggered a constructive and useful discussion here.
In between I realized my data was skewed and I wanted to apologize for
that.
The peak in load happened when I rolled out the rule-set which was
running fine on one machine to the whole cluster of 4.
I immediately blamed it on the upstream changes (sa-update) which I
recklessly incorporated last minute.
It turns out that I would have run into the same problems with the
thoroughly tested ruleset without the updates.
The reason is that the load-balancing used in this scenario is dynamic
and not round-robin as I assumed, so the other servers took the load
of the one being tested :(
That being said, it would obviously be a great improvement if I could
assess the impact of a specific ruleset before I start using it on
live data (~40M/d).
No worries. It's an idea I've had for a while and it was good to get it
publicly thrown out for comment.
Regards,
KAM