[Snort-devel] Snort 2.1.0 hangs/stops responding
Dirk at ...972...
Mon Jan 19 14:23:11 EST 2004
> I am facing a problem with SNORT 2.1.0 and even previous versions
> like 2.0.0 or 2.0.6 etc has some problem if it captures a huge amount
> of packets (100MB/min). It stops responding after running for quite
> some time. Some time, for 1-2 days and some time for couple of hours
> depending on traffic flow. I am capturing data on Gigabit ethernet
> I have only way to keep it capturing continously is by killing the
> SNORT process after about 1 hour or so. Any idea,why I am facing
> this problem.Any help will be greatly appreciated.
did you verify the process status if snort stops working?
Especially cpu usage and memory consumption would be interesting
Did you try to attach with strace (the device name eth1 sounds as
you are running linux?) to the running process (strace -p[PID])?
Where there some error messages of snort either on sdterr or
in the syslog files?
This should give at least some hints where to start debugging.
More information about the Snort-devel