Snort mailing list archives
RE: mem leak and dead snort on Sun
From: Steve Halligan <agent33 () geeksquad com>
Date: Tue, 15 May 2001 10:05:47 -0500
I have gotten a couple seg faults in spp_portscan, unfortuneatly I don't have any more info. I am hacking around with the stream3 plugin and I dismissed the crash as something I did. If I get it again I will save the info. -Steve
-----Original Message----- From: roman () danyliw com [mailto:roman () danyliw com] Sent: Tuesday, May 15, 2001 5:07 AM To: Kevin.Brown () asu edu; Ralf Hildebrandt Cc: snort-users () lists sourceforge net Subject: Re: [Snort-users] mem leak and dead snort on Sun Kevin: I just had some thoughts on spp_portscan+spo_database interaction. What is the configuration of spo_database ... log or alert? Are you logging portscans into your database? If so, how many portscan events were in your DB by the time you killed it? Ralf: What is your config? is portscan+database enabled? is portscan logging into the database (aka. is the database set to alert)? RomanI don't know what is causing this, but here goes. I setupsnort on a Netra T1and put it out in the wild. I noticed that the amount ofmemory top showsbeing eaten up by the snort process is a growing number. bash-2.03# /usr/local/bin/snort -V -*> Snort! <*- Version 1.8-beta5 (Build 20) By Martin Roesch (roesch () clark net, www.snort.org) known running plugins: spp_portscan spo_database (logs to a remote sql server) http_decode rpc_decode I started it up at 7:30 this morning (after it seemed todie last friday) andit started up with only 4MB used. By 10am it was up to128MB ram used up.Since snort stopped logging at around midnight last friday(based on theportscan logs last entry) I have been trying to figure outwhy, but can't seemto find any log entry and no core file was generated. Ican only assume thatsnort just quietly went to sleep and didn't wake up. I have noticed this behavior of snort just dieing on asecond machine put inplace to monitor one of the buildings here on campus. Ifthe level of trafficsnort is monitoring drops too low, snort just dies withouta record why. Theclosest thing to a log entry I get when snort dies on alinux box is a messagethat says that the NIC has left promiscuous mode. Any clues on this behavior of snort? _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users--------------------------------------------- This message was sent using Voicenet WebMail. http://www.voicenet.com/webmail/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- mem leak and dead snort on Sun Kevin . Brown (May 14)
- <Possible follow-ups>
- Re: mem leak and dead snort on Sun roman (May 15)
- RE: mem leak and dead snort on Sun Kevin . Brown (May 15)
- RE: mem leak and dead snort on Sun Steve Halligan (May 15)