Snort mailing list archives
Mysql process stopping affects db writes after restart of mysql?
From: "Lazarakis, Dan" <DLazarak () wcb bc ca>
Date: Wed, 10 Nov 2004 16:50:50 -0800
I noticed/tested that if mysql database process is stopped, snort (2.2) creates syslog errors that it can't write to database. Any new incidents seen by the probe do not get written to the database after that, but they do get logged in the tcpdump logfile. However, when I restart the mysql process, the incidents do not recover or get rewritten to the db (they are not spooled with error recovery) ...neither do new events after restarting mysql. It's as if I am going to have to restart snort on the probe to get logging into remote db successfully again. Anyone come across solutions for spooling alerts that don't make it into database and get snort to write to db without restarting snort? Does Barnyard handle this kind of recovery? So basically, it looks like a stopped mysql process will cause pain and lost logging into db. Dan L.
Current thread:
- Mysql process stopping affects db writes after restart of mysql? Lazarakis, Dan (Nov 10)
- Re: Mysql process stopping affects db writes after restart of mysql? Dirk Geschke (Nov 11)
- Re: Mysql process stopping affects db writes after restart of mysql? Edin Dizdarevic (Nov 11)
- Re: Mysql process stopping affects db writes after restart of mysql? Dirk Geschke (Nov 11)
