Snort mailing list archives
Re: >2Gb capture files
From: "Matthew Collins" <Matthew.Collins () northernregistrars co uk>
Date: Mon, 25 Jun 2001 12:50:49 +0100
What kernel version are you running? The 2Gb file size is a limitation of older kernels. I don't think (but I'm not certain) the 2.4 series has this problem.
"Mayers, Philip J" <p.mayers () ic ac uk> 25/06/01 10:59:46 >>>
We have a rather high-traffic site, and I just had an embarrasing experience - the snort machine runs RedHat 7.0, and I was running it under screen, so that if it dumped core, I'd see the error messages (It hasn't - nice and stable). However, once the log file reached 2Gb, snort (or glibc) stopped writing... Losing us 18 days of binary packet captures (doh!) Anyway, I have two questions: 1) Does anyone have a good snort logrotate script? 2) If I upgrade the system to RedHat 7.1, will snort/libpcap suddenly be "ok" with such large files? Regards, Phil +----------------------------------+ | Phil Mayers, Network Support | | Centre for Computing Services | | Imperial College | +----------------------------------+ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users **************************************************************************************** This message and any attachments are confidential to the ordinary user of the e-mail address to which it was addressed and may also be privileged. If you are not the addressee you may not copy, forward, disclose or use any part of the message or its attachments and if you have received this message in error, please notify the sender immediately by return e-mail and delete it from your system. Internet communications cannot be guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, arrive late or contain viruses. The sender therefore does not accept liability for any errors or omissions in the context of this message which arise as a result of Internet transmission. Northern Registrars Limited, Northern House, Woodsome Park, Fenay Bridge, Huddersfield. HD8 0LA. Tel: +44 (0) 1484 600900 Fax: +44 (0) 1484 600911 For more information visit our web site: http://www.northernregistrars.co.uk **************************************************************************************** _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- >2Gb capture files Mayers, Philip J (Jun 25)
- Re: >2Gb capture files Kiira Triea (Jun 25)
- Re: >2Gb capture files Chris Green (Jun 25)
- <Possible follow-ups>
- Re: >2Gb capture files Matthew Collins (Jun 25)
- RE: >2Gb capture files Mayers, Philip J (Jun 26)
- Re: >2Gb capture files Ralf Hildebrandt (Jun 26)