[Snort-users] snort in centos not HUPing

Jason Wallace jason.r.wallace at ...11827...
Wed Apr 13 11:44:45 EDT 2011

In Gentoo we place the PID file in /var/run/snort/<file.pid> and then
set /var/run/snort/ to be owned by the user used to run snort. If you
drop root privileges when you start snort then the snort user does not
have permissions to delete the pid file from /var/run (typically owned
by root).

That would be my guess as to what your problem is.


On Wed, Apr 13, 2011 at 10:25 AM, Agus <agus.262 at ...11827...> wrote:
> Hey guys,
> snort-2903 --enable-reload, centos5, using the rpm/snortd
> Whenever i stop snort i get the error
> snort[28654]: Could not remove pid file /var/run//snort_eth0.pid:
> Permission denied
> No biggie as it then starts ok; buttt, when i HUP snort it dies with
> that same error; so i cant HUP it.
> I googled and found solutions but for other distros that dont work with Centos.
> I tried chown snort:snort to the pid and pid.lck files but same error persists.
> Any help would be appreciated.
> Cheers,
> ------------------------------------------------------------------------------
> Forrester Wave Report - Recovery time is now measured in hours and minutes
> not days. Key insights are discussed in the 2010 Forrester Wave Report as
> part of an in-depth evaluation of disaster recovery service providers.
> Forrester found the best-in-class provider in terms of services and vision.
> Read this report now!  http://p.sf.net/sfu/ibm-webcastpromo
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users

More information about the Snort-users mailing list