Project

General

Profile

Actions

Support #1781

closed

fast.log stops updating

Added by Jon Zeolla almost 8 years ago. Updated almost 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

Numerous hours after starting my suricata service, my fast.log stops getting appended to without a crash of the service, and it will stay this way for hours until I do a manual service restart. I've attached some relevant information, but because it is timed ambiguously (anywhere between 7 and 24 hours after service start) it's hard for me to get a gdb debug, but I am working on that now. It's not core dumping and the service stays up, it's just that the fast.log stops getting appended to. If I look at stats.log, it continues to write updates, but all of the values are static until the instance is restarted.

The service is not entirely failing, which is somewhat more difficult to monitor, maintain, and debug, than if it would just crash and core dump. Some additional details are below, but I'd be more happy to gather more details as requested. I also idle in #suricata as jzeolla if it's easier to chat there and just put the results of any conversation in this thread.

Dell PowerEdge R730
- 12 cores * 2 processors w/HT (48 total)
- 192GB RAM
- 300GB usable disk space, with usage < 30%

Ubuntu 14.04.4 LTS, x86_64
- 3.13.0-85-generic

Suricata 3.0.1 RELEASE
- See attached "build-info.txt" for the output of `suricata --build-info`
- See attached "sanitized suricata.yaml" for the related suricata.yaml
- See attached "sanitized suricata.log" for a not-yet-crashed log file (as far as I can tell, when this issue hits, nothing is written to suricata.log until the service gets restarted).


Files

sanitized suricata.yaml (4 KB) sanitized suricata.yaml Jon Zeolla, 05/09/2016 10:47 AM
build-info.txt (2.82 KB) build-info.txt Jon Zeolla, 05/09/2016 11:53 AM
sanitized suricata.log (20.1 KB) sanitized suricata.log Jon Zeolla, 05/09/2016 11:55 AM
stats.log (3.72 MB) stats.log Jon Zeolla, 05/09/2016 12:51 PM
sanitized suricata 2.yaml (4 KB) sanitized suricata 2.yaml Jon Zeolla, 05/09/2016 01:06 PM
stats.log (1.63 MB) stats.log Jon Zeolla, 05/14/2016 09:58 AM
sanitized_suricata_2.log (21.1 KB) sanitized_suricata_2.log Jon Zeolla, 05/18/2016 07:12 PM
stats.log (1.06 MB) stats.log Jon Zeolla, 05/19/2016 06:06 AM
Actions

Also available in: Atom PDF