Concentrator's behind number increases rapidly when Decoder's capture rate is 3~5 Gbps. User cannot investigate recent data.
Low bandwidth between decoder and concentrator causes this problem.
'ethtool <interface>' command displays the speed is configured as 100 Mb/s which is 12.5 MB/s. (Convert bit/sec to byte/sec). 100Mb/s of speed is low for connectivity between decoder and concentrator.
# ethtool <interface> | grep Speed
Below message occur at /var/log/messages.
Dec 16 17:30:26 GP-NWForensic-Con NwConcentrator: [Bandwidth] [info] Performing bandwidth test to device <ip address of decoder>:50004...
Dec 16 17:30:28 GP-NWForensic-Con NwConcentrator: [Bandwidth] [info] Received 25 MB at a transfer rate of 11.45 MB/sec or 96.0 Mbps from device '<ip address of decoder>:50004'
Dec 16 17:30:28 GP-NWForensic-Con NwConcentrator: [Bandwidth] [warning] The bandwidth score of 96.0 Mbps is low and may cause aggregation to fall behind from device '<ip address of decoder>:50004'
The result of 'netspeed' command also displays very low (about 5~10 MB/sec).
The network administrator should change their network connectivity(switch or hub) between the decoder and concentrator from 100baseT/Full to 1000 or 10000baseT/Full. After changing the connectivity to 1000baseT/Full, netspeed results around 80~90MB/sec.
> netspeed 100MB
Response from compress command: Compression changed from 0 to 0, compression level is 0
Received 97.61 MB at a transfer rate of 97.51 MB/sec or 818 Mbps
The behind count starts to decrease after the network change.