[Snort-devel] Snort 2.1.0 hangs/stops responding

Dirk Geschke Dirk at ...972...
Mon Jan 19 14:23:11 EST 2004


Hi Manoj,

> I am facing a problem with SNORT 2.1.0 and even previous versions 
> like 2.0.0 or 2.0.6 etc has some problem if it captures a huge amount 
> of packets (100MB/min). It stops responding after running for quite 
> some time. Some time, for 1-2 days and some time for couple of hours 
> depending on traffic flow. I am capturing data on Gigabit ethernet 
> card(eth1).
> 
> I have only way to keep it capturing continously is by killing the 
> SNORT process  after about 1 hour or so. Any idea,why I am facing
> this problem.Any help will be greatly appreciated.

did you verify the process status if snort stops working?
Especially cpu usage and memory consumption would be interesting
aspects.

Did you try to attach with strace (the device name eth1 sounds as 
you are running linux?) to the running process (strace -p[PID])?

Where there some error messages of snort either on sdterr or
in the syslog files?

This should give at least some hints where to start debugging.

Best regards

Dirk Geschke





More information about the Snort-devel mailing list