> PF_RING seems to be used for the newest version of ntop for faster packet > capture and analysis. Is that what you are trying to accomplish? Yes. this is the reason why we turn back on PF_RING to patch the kernel. Generally, the libpcap can not meet our need to capture the network packets. > Or did I just get a bad google? > Sorry, what do you mean?