Re: [Snort-users] snort keeps dying!!!

This is a discussion on Re: [Snort-users] snort keeps dying!!! within the Snort forums, part of the System Security and Security Related category; --===============1961246926== Content-Type: multipart/alternative; boundary="_2012f70a-58e0-46ce-9ba3-32cfe7a5da0d_" --_2012f70a-58e0-46ce-9ba3-32cfe7a5da0d_ Content-Type: ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-06-2007
M. Shirk
 
Posts: n/a
Default Re: [Snort-users] snort keeps dying!!!

--===============1961246926==
Content-Type: multipart/alternative;
boundary="_2012f70a-58e0-46ce-9ba3-32cfe7a5da0d_"

--_2012f70a-58e0-46ce-9ba3-32cfe7a5da0d_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable



The better questions:
=0A=

=0A=
Are you trying to run ALL SIGNATURES (including bleeding threats, and the S=
tormworm IP Signatures, about 15,000 signatures)??
=0A=

=0A=
How much bandwidth is this firewall handling? (Mb/s)
=0A=

=0A=
Run Snort in non-daemon mode, and see the error you get when it stops runni=
ng.=20
=0A=

=0A=
=0A=

Shirkdog
=0A=
' or 1=3D1-- =0A=
=0A=

=0A=
http://www.shirkdog.us
> Date: Thu, 6 Sep 2007 12:20:32 -0400
> From: joel.esler@sourcefire.com
> To: titanyen2000@yahoo.com; snort-users@lists.sourceforge.net
> Subject: Re: [Snort-users] snort keeps dying!!!
>=20
> We'll probably need some kind of debug output to find out why it's dying
> since it's not printing any error messages.
>=20
> Are you running out of RAM on the box when Snort dies?
>=20
> J
>=20
>=20
> On 9/6/07 12:16 PM, "Zakai Kinan" <titanyen2000@yahoo.com> mentioned to m=

e:
>=20
> > The firewall is using Debian Etch 4.1. It is a Dell
> > PE 2950. I have nothing in the logs. Version 2.6.1.5
> > worked fine until I upgraded to latest version.
> >=20
> >=20
> > ZK
> > =20
> > --- Joel Esler <joel.esler@sourcefire.com> wrote:
> >=20
> >> What OS? What hardware? Do you have anything in
> >> your system log?
> >>=20
> >> Joel
> >>=20
> >>=20
> >> On 9/6/07 11:57 AM, "Zakai Kinan"
> >> <titanyen2000@yahoo.com> mentioned to me:
> >>=20
> >>> I just upgraded from 2.6.1.5 to 2.7.0.1 and now
> >> snort
> >>> keeps dying with no error messages. I am using
> >>> snortsam, flex_resp2, and react. I have lowered
> >> the
> >>> memory config to lowmem. The firewall has two
> >> cpus
> >>> and 4GB of ram. I start the daemaon and 2 minutes
> >>> later it stops suddenly. Has anyone else
> >> encounter
> >>> this problem?
> >>>=20
> >>> TIA,
> >>>=20
> >>> ZK
> >>>=20
> >>>=20
> >>> =20
> >>>=20
> >>=20

> > __________________________________________________ _____________________=

_______
> >>> ______
> >>> Need a vacation? Get great deals
> >>> to amazing places on Yahoo! Travel.
> >>> http://travel.yahoo.com/
> >>>=20
> >>>=20
> >>=20

> > -----------------------------------------------------------------------=

--
> >>> This SF.net email is sponsored by: Splunk Inc.
> >>> Still grepping through log files to find problems?
> >> Stop.
> >>> Now Search log events and configuration files
> >> using AJAX and a browser.
> >>> Download your FREE copy of Splunk now >>
> >> http://get.splunk.com/
> >>> _______________________________________________
> >>> Snort-users mailing list
> >>> Snort-users@lists.sourceforge.net
> >>> Go to this URL to change user options or
> >> unsubscribe:
> >>>=20
> >>=20

> > https://lists.sourceforge.net/lists/...fo/snort-users
> >>> Snort-users list archive:
> >>>=20
> >>=20

> > http://www.geocrawler.com/redir-sf.p...=3Dsnort-users
> >>>=20
> >>=20
> >> --
> >> joel esler | security consultant | Sourcefire | pgp
> >> is public
> >>=20
> >>=20
> >>=20

> >=20
> >=20
> >=20
> > =20
> > __________________________________________________ _____________________=

_______
> > ______
> > Shape Yahoo! in your own image. Join our Network Research Panel today!
> > http://surveylink.yahoo.com/gmrs/yah...vite.asp?a=3D7
> >=20
> >=20
> >=20
> > -----------------------------------------------------------------------=

--
> > This SF.net email is sponsored by: Splunk Inc.
> > Still grepping through log files to find problems? Stop.
> > Now Search log events and configuration files using AJAX and a browser.
> > Download your FREE copy of Splunk now >> http://get.splunk.com/
> > _______________________________________________
> > Snort-users mailing list
> > Snort-users@lists.sourceforge.net
> > Go to this URL to change user options or unsubscribe:
> > https://lists.sourceforge.net/lists/...fo/snort-users
> > Snort-users list archive:
> > http://www.geocrawler.com/redir-sf.p...=3Dsnort-users
> >=20

>=20
> --
> joel esler | security consultant | Sourcefire | pgp is public
>=20
>=20
>=20
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Splunk Inc.
> Still grepping through log files to find problems? Stop.
> Now Search log events and configuration files using AJAX and a browser.
> Download your FREE copy of Splunk now >> http://get.splunk.com/
> _______________________________________________
> Snort-users mailing list
> Snort-users@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/...fo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.p...=3Dsnort-users


__________________________________________________ _______________
Connect to the next generation of MSN Messenger=A0
http://imagine-msn.com/messenger/lau...3Den-us&sourc=
e=3Dwlmailtagline=

--_2012f70a-58e0-46ce-9ba3-32cfe7a5da0d_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<style>
..hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
FONT-SIZE: 10pt;
FONT-FAMILY:Tahoma
}
</style>
</head>
<body class=3D'hmmessage'><div style=3D"text-align: left;"><br></div><br><d=
iv style=3D"text-align: left;">The better questions:<br>=0A=
<br>=0A=
Are you trying to run ALL SIGNATURES (including bleeding threats, and the S=
tormworm IP Signatures, about 15,000 signatures)??<br>=0A=
<br>=0A=
How much bandwidth is this firewall handling? (Mb/s)<br>=0A=
<br>=0A=
Run Snort in non-daemon mode, and see the error you get when it stops runni=
ng. <br>=0A=
<br>=0A=
</div>=0A=
<br>Shirkdog<br>=0A=
'&nbsp;or&nbsp;1=3D1--&nbsp;=0A=
=0A=
<br>=0A=
http://www.shirkdog.us<br><hr id=3D"stopSpelling">&gt; Date: Thu, 6 Sep 200=
7 12:20:32 -0400<br>&gt; From: joel.esler@sourcefire.com<br>&gt; To: titany=
en2000@yahoo.com; snort-users@lists.sourceforge.net<br>&gt; Subject: Re: [S=
nort-users] snort keeps dying!!!<br>&gt; <br>&gt; We'll probably need some =
kind of debug output to find out why it's dying<br>&gt; since it's not prin=
ting any error messages.<br>&gt; <br>&gt; Are you running out of RAM on the=
box when Snort dies?<br>&gt; <br>&gt; J<br>&gt; <br>&gt; <br>&gt; On 9/6/0=
7 12:16 PM, "Zakai Kinan" &lt;titanyen2000@yahoo.com&gt; mentioned to me:<b=
r>&gt; <br>&gt; &gt; The firewall is using Debian Etch 4.1. It is a Dell<b=
r>&gt; &gt; PE 2950. I have nothing in the logs. Version 2.6.1.5<br>&gt; =
&gt; worked fine until I upgraded to latest version.<br>&gt; &gt; <br>&gt; =
&gt; <br>&gt; &gt; ZK<br>&gt; &gt; <br>&gt; &gt; --- Joel Esler &lt;joel.=
esler@sourcefire.com&gt; wrote:<br>&gt; &gt; <br>&gt; &gt;&gt; What OS? Wh=
at hardware? Do you have anything in<br>&gt; &gt;&gt; your system log?<br>=
&gt; &gt;&gt; <br>&gt; &gt;&gt; Joel<br>&gt; &gt;&gt; <br>&gt; &gt;&gt; <br=
>&gt; &gt;&gt; On 9/6/07 11:57 AM, "Zakai Kinan"<br>&gt; &gt;&gt; &lt;titan=

yen2000@yahoo.com&gt; mentioned to me:<br>&gt; &gt;&gt; <br>&gt; &gt;&gt;&g=
t; I just upgraded from 2.6.1.5 to 2.7.0.1 and now<br>&gt; &gt;&gt; snort<b=
r>&gt; &gt;&gt;&gt; keeps dying with no error messages. I am using<br>&gt;=
&gt;&gt;&gt; snortsam, flex_resp2, and react. I have lowered<br>&gt; &gt;=
&gt; the<br>&gt; &gt;&gt;&gt; memory config to lowmem. The firewall has tw=
o<br>&gt; &gt;&gt; cpus<br>&gt; &gt;&gt;&gt; and 4GB of ram. I start the d=
aemaon and 2 minutes<br>&gt; &gt;&gt;&gt; later it stops suddenly. Has any=
one else<br>&gt; &gt;&gt; encounter<br>&gt; &gt;&gt;&gt; this problem?<br>&=
gt; &gt;&gt;&gt; <br>&gt; &gt;&gt;&gt; TIA,<br>&gt; &gt;&gt;&gt; <br>&gt; &=
gt;&gt;&gt; ZK<br>&gt; &gt;&gt;&gt; <br>&gt; &gt;&gt;&gt; <br>&gt; &gt;&gt;=
&gt; <br>&gt; &gt;&gt;&gt; <br>&gt; &gt;&gt; <br>&gt; &gt; _________=
__________________________________________________ ___________________<br>&g=
t; &gt;&gt;&gt; ______<br>&gt; &gt;&gt;&gt; Need a vacation? Get great deal=
s<br>&gt; &gt;&gt;&gt; to amazing places on Yahoo! Travel.<br>&gt; &gt;&gt;=
&gt; http://travel.yahoo.com/<br>&gt; &gt;&gt;&gt; <br>&gt; &gt;&gt;&gt; <b=
r>&gt; &gt;&gt; <br>&gt; &gt; ---------------------------------------------=
----------------------------<br>&gt; &gt;&gt;&gt; This SF.net email is spon=
sored by: Splunk Inc.<br>&gt; &gt;&gt;&gt; Still grepping through log files=
to find problems?<br>&gt; &gt;&gt; Stop.<br>&gt; &gt;&gt;&gt; Now Search =
log events and configuration files<br>&gt; &gt;&gt; using AJAX and a browse=
r.<br>&gt; &gt;&gt;&gt; Download your FREE copy of Splunk now &gt;&gt;<br>&=
gt; &gt;&gt; http://get.splunk.com/<br>&gt; &gt;&gt;&gt; __________________=
_____________________________<br>&gt; &gt;&gt;&gt; Snort-users mailing list=
<br>&gt; &gt;&gt;&gt; Snort-users@lists.sourceforge.net<br>&gt; &gt;&gt;&gt=
; Go to this URL to change user options or<br>&gt; &gt;&gt; unsubscribe:<br=
>&gt; &gt;&gt;&gt; <br>&gt; &gt;&gt; <br>&gt; &gt; https://lists.sourceforg=

e.net/lists/listinfo/snort-users<br>&gt; &gt;&gt;&gt; Snort-users list arch=
ive:<br>&gt; &gt;&gt;&gt; <br>&gt; &gt;&gt; <br>&gt; &gt; http://www.geocra=
wler.com/redir-sf.php3?list=3Dsnort-users<br>&gt; &gt;&gt;&gt; <br>&gt; &gt=
;&gt; <br>&gt; &gt;&gt; --<br>&gt; &gt;&gt; joel esler | security consultan=
t | Sourcefire | pgp<br>&gt; &gt;&gt; is public<br>&gt; &gt;&gt; <br>&gt; &=
gt;&gt; <br>&gt; &gt;&gt; <br>&gt; &gt; <br>&gt; &gt; <br>&gt; &gt; <br>&gt=
; &gt; <br>&gt; &gt; ________________________________________________=
______________________________<br>&gt; &gt; ______<br>&gt; &gt; Shape Yahoo=
! in your own image. Join our Network Research Panel today!<br>&gt; &gt; h=
ttp://surveylink.yahoo.com/gmrs/yahoo_panel_invite.asp?a=3D7<br>&gt; &gt; <=
br>&gt; &gt; <br>&gt; &gt; <br>&gt; &gt; ----------------------------------=
---------------------------------------<br>&gt; &gt; This SF.net email is s=
ponsored by: Splunk Inc.<br>&gt; &gt; Still grepping through log files to f=
ind problems? Stop.<br>&gt; &gt; Now Search log events and configuration f=
iles using AJAX and a browser.<br>&gt; &gt; Download your FREE copy of Splu=
nk now &gt;&gt; http://get.splunk.com/<br>&gt; &gt; ______________________=
_________________________<br>&gt; &gt; Snort-users mailing list<br>&gt; &gt=
; Snort-users@lists.sourceforge.net<br>&gt; &gt; Go to this URL to change u=
ser options or unsubscribe:<br>&gt; &gt; https://lists.sourceforge.net/list=
s/listinfo/snort-users<br>&gt; &gt; Snort-users list archive:<br>&gt; &gt; =
http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users<br>&gt; &gt; <br=
>&gt; <br>&gt; --<br>&gt; joel esler | security consultant | Sourcefire | p=

gp is public<br>&gt; <br>&gt; <br>&gt; <br>&gt; ---------------------------=
----------------------------------------------<br>&gt; This SF.net email is=
sponsored by: Splunk Inc.<br>&gt; Still grepping through log files to find=
problems? Stop.<br>&gt; Now Search log events and configuration files usi=
ng AJAX and a browser.<br>&gt; Download your FREE copy of Splunk now &gt;&g=
t; http://get.splunk.com/<br>&gt; ________________________________________=
_______<br>&gt; Snort-users mailing list<br>&gt; Snort-users@lists.sourcefo=
rge.net<br>&gt; Go to this URL to change user options or unsubscribe:<br>&g=
t; https://lists.sourceforge.net/lists/listinfo/snort-users<br>&gt; Snort-u=
sers list archive:<br>&gt; http://www.geocrawler.com/redir-sf.php3?list=3Ds=
nort-users<br><br /><hr />Connect to the next generation of MSN Messenger=
=A0 <a href=3D'http://imagine-msn.com/messenger/launch80/default.aspx?loca=
le=3Den-us&source=3Dwlmailtagline' target=3D'_new'>Get it now! </a></body>
</html>=

--_2012f70a-58e0-46ce-9ba3-32cfe7a5da0d_--


--===============1961246926==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems? Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
--===============1961246926==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
--===============1961246926==--

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:42 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0