Thanks - the scanner analysis logs have wrapped but it does not matter - i can see what is happening
It is an issue. With the curl change we are ending up using 9 tcp ports per episode instead of 3.
The logs show 20 files a second are being analyzed - so using up at least 180 ports a second - instead of 60.
I will see if there is any movement on the curl issue.
Without the curl issue and with the current speed it will be marginal as we would be using up about 14000 ports in 4 minutes - by this time some previously used ports should get returned to the pool (TIME_WAIT)
Would like to know the exact time the 4227 event was first flagged - at 16:12 so i can count the number of requests to that time.