Koozali.org: home of the SME Server
Obsolete Releases => SME 7.x Contribs => Topic started by: Stiven on August 05, 2008, 04:33:32 PM
-
Hi,
As you can read in the subject the cpu usage of my sme box is around 100% when snort is running.
Is someone can help me please.
Thanx in advance.
FYI : smeserver-snort-2.7.0.1-1 + smeserver-oinkmaster-1.2-2 + smeserver-guardiand-1.7-4 + smeserver-base-1.2.2-1
Tell me if you need some pieces of log for diagnosys
-
Hi,
As you can read in the subject the cpu usage of my sme box is around 100% when snort is running.
Is someone can help me please.
Thanx in advance.
FYI : smeserver-snort-2.7.0.1-1 + smeserver-oinkmaster-1.2-2 + smeserver-guardiand-1.7-4 + smeserver-base-1.2.2-1
Tell me if you need some pieces of log for diagnosys
100% of processor utilization is not necessarily a bad thing on linux, how long does it stay at 100%, does it also slow down other processes? Linux has a far better prioritization system for processes than windows.
-
I installed snort once years ago, and found that after a while (weeks or months) the number of files in the snort log folder reached a point where starting snort would generate hours of disk thrashing as it tried to do something with the log files...
I believe this was addressed in the SME snort contrib quite a while ago.
Are you running a SME 'snort' contrib, or have you installed snort manually?
-
how long does it stay at 100%,
Ever
does it also slow down other processes?
I don't really know but I suppose
Linux has a far better prioritization system for processes than windows.
Yes it has.
Are you running a SME 'snort' contrib, or have you installed snort manually?
The answer is in my first post.
-
UP
-
As you can read in the subject the cpu usage of my sme box is around 100% when snort is running.
I'd suggest you remove snort, and just use your time ensuring that you don't install insecure software on your server.
-
check the rule defination auto download by the oinkmaster, it is always teh current version, and when the version change, the rule that does not matchs the snort version you are using will make the server run at 100%.
Check out the script file and point it to the correct version..... I forgot how as it happen so long before.....
Hope this help.