Snort mailing list archives

HUP causes wierd msgs in snort-1.8.1-beta6


From: Jason Haar <Jason.Haar () trimble co nz>
Date: Wed, 8 Aug 2001 09:28:03 +1200

I'm logging sessions via:

preprocessor stream4: detect_scans, keepstats machine, timeout 30, memcap 8388608

Given the size session.log can become, I rotate that nightly and flush the
log via a HUP to snort.

When snort receives the HUP, it logs this:

-*> Snort! <*-
Version 1.8.1-beta6 (Build 60)
By Martin Roesch (roesch () sourcefire com, www.snort.org)
<bunch of binary chars follow>

WARNING: _PATH_VARRUN is invalid, trying /var/log...
WARNING: /var/log/ is invalid, logging Snort PID to log directory
(/var/log/snort)
ERROR: OpenPcap() device eth0 open: 
socket: Operation not permitted
Fatal Error, Quitting..

Issues with HUP seem to come up a bit. Just what can be done with snort
running as a non-root user? What signals work as expected?

This is running in a chroot'ed jail, and I've made /var owned by the snort
account, so I cannot understand what all those warnings are about PID
entries either...

Help?

-- 
Cheers

Jason Haar

Unix/Special Projects, Trimble NZ
Phone: +64 3 9635 377 Fax: +64 3 9635 417

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: