Snort stopped working again (last update)



  • Snort stopped today:
    2.1-BETA0 (i386)
    built on Sat Jul 21 08:37:06 EDT 2012
    FreeBSD 8.3-RELEASE-p3

    You are on the latest version.

    It was fine before that release.



  • The problem is still there.

    Even if I uninstall & re-install.

    2.1-BETA0 (i386)
    built on Sun Jul 22 13:36:58 EDT 2012
    FreeBSD 8.3-RELEASE-p3



  • Snort is still broken, 2.9.2.3 pkg v.2.5.1 (snort-2.9.2.3-i386.pbi 2012-Jul-17 21:37:45 10.7M).

    2.1-BETA0 (i386)
    built on Tue Jul 24 08:20:58 EDT 2012
    FreeBSD 8.3-RELEASE-p3



  • Did snort uninstall, deleted /usr/local/lib/snort, re-install + update, then:

    ./snort.sh start
    pgrep: Pidfile `/var/run/snort_pppoe059419.pid' is empty

    Same error.  ???



  • Same with snort-dev, and the dashboard widget throws this error:

    Crash report begins.  Anonymous machine information:

    amd64
    8.3-RELEASE-p3
    FreeBSD 8.3-RELEASE-p3 #1: Tue Jul 24 09:42:54 EDT 2012    root@FreeBSD_8.3_pfSense_2.1.snaps.pfsense.org:/usr/obj./usr/pfSensesrc/src/sys/pfSense_SMP.8

    Crash report details:

    PHP Errors:
    [24-Jul-2012 19:56:11 UTC] PHP Fatal error:  Call to undefined function snort_get_blocked_ips() in /usr/local/www/widgets/widgets/snort_alerts.widget.php on line 41
    [24-Jul-2012 20:04:08 UTC] PHP Fatal error:  Call to undefined function snort_get_blocked_ips() in /usr/local/www/widgets/widgets/snort_alerts.widget.php on line 41

    Filename: /var/crash/minfree
    2048



  • I read with AMD snort never worked very well (yes, something odd), however I'm on Intel (P4 3.6GHz).



  • @rcfa snort and snort-dev are different animals now. The widget wont work with snort-dev because the alert log is different for both now. The dev needs to fix the package based on the binary changes that have been made since they both use the same binary.. I've giving up on snort-dev for now.



  • I'm not using snort-dev btw.

    And still getting the boring:
    pgrep: Pidfile `/var/run/snort_pppoe059419.pid' is empty

    Error.   >:(



  • Sigh.

    Fixed.



  • @Gradius:

    Sigh.

    Fixed.

    It is working for me on a test box I have. Snort Auto updates enabled every 6 hours no problems.
    Snort not snort-dev

    intel atom 8 gig memory 64 gig ssd.
    2.1-BETA0 (amd64)
    built on Wed Jul 25 09:38:52 EDT 2012


Log in to reply