Snort mailing list archives
Re: Snort 2.6.1 Stops Logging
From: "Colin Grady" <colin.grady () gmail com>
Date: Tue, 21 Nov 2006 20:25:31 -0600
On that note... The system I'm testing Snort 2.6.1 on is also an SMP system, but running Debian and compiled with the Phil Wood's pcap patch ( http://public.lanl.gov/cpw/). Colin Grady On 11/21/06, Eric J. Feldhusen <efeldhusen.lists () gmail com> wrote:
Jason Haar wrote: > Colin Grady wrote: >> I've migrated one system from Snort 2.6.0.2 <http://2.6.0.2> to Snort >> 2.6.1. I've made no configuration file changes and no command-line >> changes between the two releases, but after somewhere around 20-30 >> minutes after being started Snort 2.6.1 seems to stop logging data. >> I'm using unified logging, which is being processed through Barnyard. >> The Snort process continues to run and the processor time continues to >> climb, but the unified logs stop growing -- so it's not related to >> Barnyard as best as I can tell. >> >> Anyone else seen anything like this? > > I think this is a "me too". I've just noticed that 2.6.1RC1 appears to > work initially, but stops logging at some later time. I am just > upgrading to 2.6.1 to see if that fixes it - but your report implies it > won't. We're using both syslog and mysql output modules - and both stop > reporting - so that (plus your barnyard report) implies the problem is > occurring somewhere earlier on. > > This is snort-2.6.1RC1 under CentOS4.4 I've got a RHEL4u4 server with dual xeons with hyperthreading on, with snort-2.6.1 with mysql logging only and using Base 1.2.7 , and I've seen similar problems, the snortd process will run for about 20-120 minutes at a using 5-8% of the cpu, and then I'll check back later in the day and snortd process load is at 100%. I've been shutting of more and more included rule sets to see if it's a particular rule causing the problem. I'll have to try and see if I shut off all rules if it happens. Eric Feldhusen ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort 2.6.1 Stops Logging Colin Grady (Nov 21)
- Re: Snort 2.6.1 Stops Logging Jason Haar (Nov 21)
- Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen (Nov 21)
- Re: Snort 2.6.1 Stops Logging Colin Grady (Nov 21)
- Re: Snort 2.6.1 Stops Logging Martin Roesch (Nov 21)
- Re: Snort 2.6.1 Stops Logging Jason Haar (Nov 22)
- Re: Snort 2.6.1 Stops Logging Eric Feldhusen (Nov 22)
- Message not available
- Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen (Nov 22)
- Message not available
- Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen (Nov 22)
- Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen (Nov 21)
- Re: Snort 2.6.1 Stops Logging Jason Haar (Nov 21)
