I got snort up and running on my ubuntu server. I use BASE to view the data which is running on apache2 php5 and mysql. I thought I would update the rules so I installed oinkmaster and got myself an id. I updated the rules (which seemed to go allright). I restarted snort, and then it happened. My cpu goes running full speed and after I short while I get allot of disk i/o's. Then I get an out of memory error for snort (I thought I got it for mysql as well a few times but I can't reproduce that anymore). When viewing BASE I see no entries between boot and crash.
this is my database entry in my snort.conf:
Code:
output database: log, mysql, user=snort password=XXXXXXXX dbname=snort host=localhost
I did not make many modifications to snort.conf, and it was running fine before the oinkmaster update.
I have no idea on what to do, how to diagnose the problem, find the cause and how to fix it.
Help would be very much apreciated.
Bookmarks