Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 4th March 2009, 10:20 AM
Thaidog Offline
Registered User
 
Join Date: Feb 2006
Posts: 184
Question snort dead but subsys locked

I am trying to get snort running but I get this with service snortd status:

snort dead but subsys locked

service snortd restart

Stopping snort: [FAILED]
Starting snort: [ OK ]

[root@Fedora tylerm]# tail -f /var/log/messages
Mar 4 05:17:54 Fedora kernel: device eth0 entered promiscuous mode
Mar 4 05:17:54 Fedora kernel: device eth0 left promiscuous mode
Mar 4 05:17:54 Fedora snort[3280]: Initializing daemon mode
Mar 4 05:17:54 Fedora kernel: device eth0 entered promiscuous mode
Mar 4 05:17:54 Fedora snort[3282]: PID path stat checked out ok, PID path set to /var/run/
Mar 4 05:17:54 Fedora snort[3282]: Writing PID "3282" to file "/var/run//snort_eth0.pid"
Mar 4 05:17:54 Fedora snort[3282]: Daemon initialized, signaled parent pid: 3280
Mar 4 05:17:54 Fedora snort[3280]: Daemon parent exiting
Mar 4 05:17:54 Fedora snort[3282]: FATAL ERROR: OpenAlertFile() => fopen() alert file /var/log/snort/alert: Permission denied
Mar 4 05:17:54 Fedora kernel: device eth0 left promiscuous mode
Mar 4 05:18:42 Fedora ntpd[2300]: synchronized to 128.10.19.24, stratum 1
Mar 4 05:18:42 Fedora ntpd[2300]: time reset +0.906114 s
Mar 4 05:18:42 Fedora ntpd[2300]: kernel time sync status change 0001


Any ideas?
Reply With Quote
  #2  
Old 19th March 2009, 09:48 PM
shashanknigam Offline
Registered User
 
Join Date: Mar 2009
Posts: 1
Hi.....
You can resolve this problem by making few changes in snort. You have to just give Anonymous read/write permission to directory /var/log/snort/

Thanks,
Shashank Nigam
Reply With Quote
  #3  
Old 20th March 2009, 10:05 AM
Thaidog Offline
Registered User
 
Join Date: Feb 2006
Posts: 184
I solved this a few weeks ago actually. I changed the owner of alert to snortd. I'm not sure it would be a good idea to open up the permissions like you are saying though... ?
Reply With Quote
Reply

Tags
dead, locked, snort, subsys

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
mysqld dead but subsys locked einnox Servers & Networking 10 11th February 2011 05:43 AM
icecast dead but subsys locked frojd Servers & Networking 0 1st May 2008 11:05 PM
amavisd dead but subsys locked asyadiqin Installation and Live Media 0 15th January 2007 03:27 PM


Current GMT-time: 17:35 (Monday, 20-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat