Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    snort running to half stop many times a day

    Scheduled Pinned Locked Moved IDS/IPS
    23 Posts 6 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      blackkep
      last edited by

      kernel pid 23034 (snort), jid 0, uid 0: exited on signal 11 (core dumped)
      kernel em1: promiscuous mode disabled

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @blackkep
        last edited by

        @blackkep Arm hardware?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        B 1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by bmeeks

          What does "snort running to half ..." mean? I do not understand.

          You also did not supply any helpful information for further troubleshooting.

          1. What version of pfSense are you on?

          2. What kind of hardware are you using (ARM or AMD64 CPU)?

          3. What version of the Snort package are you running?

          4. Are there any other Snort-related messages in the pfSense system log around the time of the crash?

          B 1 Reply Last reply Reply Quote 0
          • B
            blackkep @bmeeks
            last edited by

            @bmeeks
            Update Your Rule Set that's all
            1.23.01-RELEASE (amd64)
            2.Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
            3.4.1.6_7
            4.未命名.jpg

            bmeeksB 1 Reply Last reply Reply Quote 0
            • B
              blackkep @SteveITS
              last edited by

              @steveits
              CPU:Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
              RAM:8G
              Disks:SSD 512GB

              1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks @blackkep
                last edited by

                @blackkep said in snort running to half stop many times a day:

                @bmeeks
                Update Your Rule Set that's all
                1.23.01-RELEASE (amd64)
                2.Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
                3.4.1.6_7
                4.未命名.jpg

                If it crashes on a rules update, that would point toward a faulty rule getting downloaded and enabled.

                Once it crashes, can you start it up manually using the GUI icons on the INTERFACES tab in Snort?

                If not, you may have to start a process of elimination by disabling rule categories one-at-the-time until Snort starts successfully.

                B 1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee
                  last edited by JonathanLee

                  You might have to many rules added.

                  For me I use this just the recommended IPS and Emerging threats lists. I too had to issues with memory use with more rulesets. Again I only have 4GBs

                  Screenshot 2023-05-08 at 7.38.13 PM.png

                  Screenshot 2023-05-08 at 7.38.44 PM.png

                  Screenshot 2023-05-08 at 7.40.48 PM.png

                  There was a time when I wanted to run all of them but my memory made me give up the APPid stuff it eats memory

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • B
                    blackkep @bmeeks
                    last edited by blackkep

                    @bmeeks @jonathanlee
                    thank you solved it

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      Patch @blackkep
                      last edited by

                      @blackkep said in snort running to half stop many times a day:

                      thank you solved it

                      Out of interest what change actually fixed it

                      B 1 Reply Last reply Reply Quote 0
                      • B
                        blackkep @Patch
                        last edited by

                        @patch
                        There is a rule to turn off snort can be normal

                        Might have to wait until the next update to enable this rule

                        fireodoF 1 Reply Last reply Reply Quote 0
                        • fireodoF
                          fireodo @blackkep
                          last edited by

                          @blackkep said in snort running to half stop many times a day:

                          There is a rule to turn off snort can be normal

                          And wich one? Can you tell us too?

                          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                          pfsense 2.7.2 CE
                          Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                          B 1 Reply Last reply Reply Quote 0
                          • B
                            blackkep @fireodo
                            last edited by

                            @fireodo After you update the rules also ?

                            emerging-drop.rules

                            fireodoF S 2 Replies Last reply Reply Quote 0
                            • fireodoF
                              fireodo @blackkep
                              last edited by fireodo

                              @blackkep said in snort running to half stop many times a day:

                              @fireodo After you update the rules also ?

                              From time to time Snort exits on rules update (here) with signal 11 but it will continuing running normal.

                              emerging-drop.rules

                              Thanks. (not enabled here)

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.7.2 CE
                              Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                              B 1 Reply Last reply Reply Quote 0
                              • B
                                blackkep @fireodo
                                last edited by blackkep

                                @fireodo This bug has been around for a long time

                                1 Reply Last reply Reply Quote 1
                                • S
                                  SteveITS Galactic Empire @blackkep
                                  last edited by

                                  @blackkep If you want an alternative for DROP, you can use pfBlocker and pick DROP from its feed list. Then create a regular firewall block rule via the feed set as Alias Native, or have it create the rule via Deny.

                                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                  Upvote 👍 helpful posts!

                                  B 2 Replies Last reply Reply Quote 2
                                  • B
                                    blackkep @SteveITS
                                    last edited by

                                    @steveits 33228368-d56c-4be4-bafa-858990955986-image.png The DROP rule is still running ?

                                    S 1 Reply Last reply Reply Quote 0
                                    • B
                                      blackkep @SteveITS
                                      last edited by

                                      @steveits pfblockerng DROP I see the original list

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        SteveITS Galactic Empire @blackkep
                                        last edited by

                                        @blackkep said in snort running to half stop many times a day:

                                        @steveits The DROP rule is still running ?

                                        Not sure I understand the question…if you are using pfBlocker you can disable the category in Snort. No need to scan twice.

                                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                        Upvote 👍 helpful posts!

                                        B 1 Reply Last reply Reply Quote 0
                                        • B
                                          blackkep @SteveITS
                                          last edited by

                                          @steveits It is very strange that snort has canceled the DROP rule and is still running

                                          S 1 Reply Last reply Reply Quote 0
                                          • S
                                            SteveITS Galactic Empire @blackkep
                                            last edited by

                                            @blackkep Did you restart Snort in that interface to pick up the new settings? Check if multiple Snort processes are running and if so end them or restart your router.

                                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                            Upvote 👍 helpful posts!

                                            B 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.