[Snort-users] corrupt table problem with snort, mysql, acid and ssh setup

VAUGHAN MOSELEY moseleyv at ...11827...
Thu Jan 27 15:42:19 EST 2005


Hi
I'm remotely administering a fedora 2 snort box via ssh.
running snort with
snort -c /etc.snort/snort.conf is fine - that is everything is logged
to tables and shows in acid.

But if i leave it running for over about a minute it buggers up. I
lose my ssh and acid/apache service. I then have to get a guy from
down the road to go and restart the thing for me. When I restart it i
get this error message in acid:

database: mysql_error: Got error 127 from table handler

But nothing in mysqld.log

This box is checking quite alot of traffic and i have minimised the
rules to check against.
when i run it for about 30 seconds it will not crash ssh or acid and
acid can read the tables but everytime i do myisamchk afterwards i get
:

myisamchk: warning: 1 clients is using or hasn't closed the table
properly
MyISAM-table '/var/lib/mysql/snort/acid_ip_cache.MYI' is usable but
should be fixed
myisamchk: error: Size of datafile is: 0                 Should be:
4011
myisamchk: error: Found key at page 2048 that points to record outside
datafile
MyISAM-table '/var/lib/mysql/snort/event.MYI' is corrupted
Fix it using switch "-r" or "-o"
myisamchk: error: Size of datafile is: 0                 Should be:
6112
myisamchk: error: Found key at page 2048 that points to record outside
datafile
MyISAM-table '/var/lib/mysql/snort/iphdr.MYI' is corrupted
Fix it using switch "-r" or "-o"

There are similar errors for most tables not just the 3 here.
I don't think the guy up the road will go and restart it for me again
so would appreciate any help. Could this be reaching maximum table
cache or memory of some sort so not closing the tables properly? I can
myisamchk recover tables and it will be fine but i'd like to run snort
for longer and not have to worry about losing my remote connection.




More information about the Snort-users mailing list