<div dir="ltr">Maybe another important information, the HOME_NET variable is set by "include homenet.yaml" file.<br></div><br><div class="gmail_quote"><div dir="ltr">On Mon, Sep 17, 2018 at 5:07 PM Breno Silva <<a href="mailto:breno.silva@gmail.com">breno.silva@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">I'm looking to my logs and it takes ~100 reloads to crash.<div>But not sure if amount of rules will change it or not.</div></div><br><div class="gmail_quote"><div dir="ltr">On Mon, Sep 17, 2018 at 5:06 PM Breno Silva <<a href="mailto:breno.silva@gmail.com" target="_blank">breno.silva@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Victor,<div><br></div><div>Suricata 4.0.4</div><div>It reports : </div><div><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">11/9/2018 -- 13:11:22 - <Notice> - rule reload complete</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">11/9/2018 -- 13:11:48 - <Notice> - rule reload starting</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">11/9/2018 -- 13:12:19 - <Error> - [ERRCODE: SC_ERR_MEM_ALLOC(1)] - Error allocating memory</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">...</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 07:38:49 - <Notice> - rule reload complete</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 07:39:46 - <Notice> - rule reload starting</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 07:40:17 - <Error> - [ERRCODE: SC_ERR_MEM_ALLOC(1)] - Error allocating memory</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">...</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 10:01:54 - <Notice> - rule reload complete</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 10:02:52 - <Notice> - rule reload starting</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 10:03:24 - <Error> - [ERRCODE: SC_ERR_MEM_ALLOC(1)] - Error allocating memory</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">...</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 14:00:09 - <Notice> - rule reload complete</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 14:01:04 - <Notice> - rule reload starting</span><br style="box-sizing:border-box;outline:none;color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)"><span style="color:rgb(51,51,51);font-family:Lato,sans-serif;font-size:13px;background-color:rgb(213,213,213)">12/9/2018 -- 14:01:37 - <Error> - [ERRCODE: SC_ERR_MEM_ALLOC(1)] - Error allocating memory</span><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Mon, Sep 17, 2018 at 5:01 PM Victor Julien <<a href="mailto:lists@inliniac.net" target="_blank">lists@inliniac.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 17-09-18 21:55, Breno Silva wrote:<br>
> I have a tool that monitor all my interfaces ipv4/ipv6 addresses and<br>
> when they change, the tool re-define HOMET_NET and send signal to<br>
> suricata for rule reloading. Looks like there is a memory leak when it<br>
> happens and suricata process memory increase until crash.<br>
> <br>
> All yaml files exists and are successfully loaded.<br>
<br>
Can you add some relevant info? What suri version, what did you try<br>
already, how often does it reload before the crash, what kind of crash, etc?<br>
<br>
-- <br>
---------------------------------------------<br>
Victor Julien<br>
<a href="http://www.inliniac.net/" rel="noreferrer" target="_blank">http://www.inliniac.net/</a><br>
PGP: <a href="http://www.inliniac.net/victorjulien.asc" rel="noreferrer" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
---------------------------------------------<br>
<br>
_______________________________________________<br>
Suricata IDS Devel mailing list: <a href="mailto:oisf-devel@openinfosecfoundation.org" target="_blank">oisf-devel@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" rel="noreferrer" target="_blank">http://suricata-ids.org</a> | Participate: <a href="http://suricata-ids.org/participate/" rel="noreferrer" target="_blank">http://suricata-ids.org/participate/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel" rel="noreferrer" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel</a><br>
Redmine: <a href="https://redmine.openinfosecfoundation.org/" rel="noreferrer" target="_blank">https://redmine.openinfosecfoundation.org/</a><br>
<br>
</blockquote></div>
</blockquote></div>
</blockquote></div>