Netgate SG-1000 microFirewall

Author Topic: Snort exited on signal 11  (Read 61 times)

0 Members and 1 Guest are viewing this topic.

Offline sboyle

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Snort exited on signal 11
« on: February 09, 2018, 11:30:01 am »
I have an issue where Snort exits when it updates rules.  I can manually start it and it starts and runs fine, until the next update when it fails again.

Here is what I see in the logs:
Feb 8 12:05:23   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] The Rules update has finished.
Feb 8 12:05:22   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Building new file for LAN...
Feb 8 12:05:22   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Enabling any flowbit-required rules for: LAN...
Feb 8 12:05:20   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Updating rules configuration for: LAN ...
Feb 8 12:05:20   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Removed 49 obsoleted rules category files.
Feb 8 12:05:20   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Hide Deprecated Rules is enabled. Removing obsoleted rules categories.
Feb 8 12:05:18   kernel      pid 3372 (snort), uid 0: exited on signal 11
Feb 8 12:05:14   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Emerging Threats Open rules are up to date...
Feb 8 12:05:14   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Snort OpenAppID detectors are up to date...
Feb 8 12:05:11   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] Snort VRT rules file update downloaded successfully
Feb 8 12:05:00   php      /usr/local/pkg/snort/snort_check_for_rule_updates.php: [Snort] There is a new set of Snort VRT rules posted. Downloading snortrules-snapshot-2990.tar.gz...

The update completes but Snort is not running after that.  I would appreciate any suggestions.