When you decreased the number of snort processes from 4 to 2, did you
follow the instructions here?
https://code.google.com/p/security-onion/wiki/PF_RING#Snort/Suricata
Specifically, did you run nsm_sensor_ps-stop before modifying
sensor.conf? If not, then the old agents are still running. You can
either find their processes and kill them manually or just reboot the
box.
On Mon, Jan 12, 2015 at 4:07 PM, Brian Kellogg <
thef...@gmail.com> wrote:
> Thanks Doug,
>
> Unfortunately that didn't work. I tried just deactivating via the hostname and not the net_name as I assume the later will set the ones that are still active as inactive. I did restart Sguil server.
>