Snort mailing list archives

corrupt table problem with snort, mysql, acid and ssh setup


From: VAUGHAN MOSELEY <moseleyv () gmail com>
Date: Thu, 27 Jan 2005 14:56:28 +0000

I'm remotely administering a fedora 2 snort box via ssh.
running snort with
snort -c /etc.snort/snort.conf is fine - that is everything is logged
to tables and shows in acid.

But if i leave it running for over about a minute it buggers up. I
lose my ssh and acid/apache service. I then have to get a guy from
down the road to go and restart the thing for me. When I restart it i
get this error message in acid:

database: mysql_error: Got error 127 from table handler

But nothing in mysqld.log

This box is checking quite alot of traffic and i have minimised the
rules to check against.
when i run it for about 30 seconds it will not crash ssh or acid and
acid can read the tables but everytime i do myisamchk afterwards i get
:

myisamchk: warning: 1 clients is using or hasn't closed the table
properly
MyISAM-table '/var/lib/mysql/snort/acid_ip_cache.MYI' is usable but
should be fixed
myisamchk: error: Size of datafile is: 0                 Should be:
4011
myisamchk: error: Found key at page 2048 that points to record outside
datafile
MyISAM-table '/var/lib/mysql/snort/event.MYI' is corrupted
Fix it using switch "-r" or "-o"
myisamchk: error: Size of datafile is: 0                 Should be:
6112
myisamchk: error: Found key at page 2048 that points to record outside
datafile
MyISAM-table '/var/lib/mysql/snort/iphdr.MYI' is corrupted
Fix it using switch "-r" or "-o"

There are similar errors for most tables not just the 3 here.
I don't think the guy up the road will go and restart it for me again
so would appreciate any help. Could this be reaching maximum table
cache or memory of some sort so not closing the tables properly? I can
myisamchk recover tables and it will be fine but i'd like to run snort
for longer and not have to worry about losing my remote connection.


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: