• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort memory usage drops by %50

Scheduled Pinned Locked Moved IDS/IPS
12 Posts 4 Posters 2.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    fantasypoo
    last edited by Nov 14, 2015, 1:16 PM

    Does anyone know why when starting the snort process my memory usage goes up to %69 and then after a few days its down to about %20-30.  Is this normal… shouldnt it stay at %69 ?!
    I'm running it in AC mode so that it uses more memory on purpose.

    1 Reply Last reply Reply Quote 0
    • B
      BBcan177 Moderator
      last edited by Nov 14, 2015, 1:38 PM

      At startup, Snort will use more memory as it is configuring and loading all of its settings. Recommend also to use "AC-BNFA-NQ".

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • F
        fantasypoo
        last edited by Nov 14, 2015, 3:11 PM

        @BBcan177:

        At startup, Snort will use more memory as it is configuring and loading all of its settings. Recommend also to use "AC-BNFA-NQ".

        Thanks, I prefer AC because I have the pfsense model C2758 and it has 8gb of ram.

        1 Reply Last reply Reply Quote 0
        • B
          BBcan177 Moderator
          last edited by Nov 14, 2015, 3:13 PM

          There are issues with using "AC", even if RAM is available…

          Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • F
            fantasypoo
            last edited by Nov 14, 2015, 3:16 PM

            @BBcan177:

            There are issues with using "AC", even if RAM is available…

            Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

            thx for the tip!
            how much ram do you have ?

            1 Reply Last reply Reply Quote 0
            • B
              BBcan177 Moderator
              last edited by Nov 14, 2015, 3:21 PM

              @fantasypoo:

              @BBcan177:

              There are issues with using "AC", even if RAM is available…

              Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

              thx for the tip!
              how much ram do you have ?

              Several different boxes in the range of 3GB, 4GB, 8GB, 32GB…

              Even at 32GB, "AC" was causing issues, plus it takes forever to reload the Snort config when using "AC". It also caused some random Snort crashes with no particular log errors to debug... My 2cents!

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • F
                fantasypoo
                last edited by Nov 14, 2015, 3:24 PM

                @fantasypoo:

                @BBcan177:

                There are issues with using "AC", even if RAM is available…

                Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

                thx for the tip!
                how much ram do you have ?

                https://forum.pfsense.org/index.php?topic=75216.msg410701#msg410701
                I read this forum post and the suggestion was more ram.  I have ordered another 8gb ECC ram …hopefully this will be the cure for running it in AC mode.

                1 Reply Last reply Reply Quote 0
                • B
                  bmeeks
                  last edited by Nov 15, 2015, 2:04 AM

                  No modes other than AC-BNFA or AC-BNFA-NQ are recommended.  Expect problems with AC mode.  Don't know why, but it just seems to gobble up RAM and does not really boost performance much – certainly not enough of a boost to justify the random issues it causes.

                  Bill

                  1 Reply Last reply Reply Quote 0
                  • F
                    fantasypoo
                    last edited by Nov 15, 2015, 3:30 AM

                    @bmeeks:

                    No modes other than AC-BNFA or AC-BNFA-NQ are recommended.  Expect problems with AC mode.  Don't know why, but it just seems to gobble up RAM and does not really boost performance much – certainly not enough of a boost to justify the random issues it causes.

                    Bill

                    hmm.. does the same apply to Suricata ?  Default is AC

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by Nov 15, 2015, 8:37 AM

                      AC-BNFA-NQ is not available in Suricata.

                      1 Reply Last reply Reply Quote 0
                      • F
                        fantasypoo
                        last edited by Nov 15, 2015, 2:04 PM

                        I will upgrade to 32gb ram over the coming weeks…  I may sound like a raving lunatic but I can't stand for this "AC-BNFA-NQ"

                        1 Reply Last reply Reply Quote 0
                        • B
                          bmeeks
                          last edited by Nov 16, 2015, 1:21 PM

                          @fantasypoo:

                          hmm.. does the same apply to Suricata ?  Default is AC

                          Suricata is a completely different binary code base.  You can't really compare the two in this area.

                          Bill

                          1 Reply Last reply Reply Quote 0
                          12 out of 12
                          • First post
                            12/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received