racluster crash

Dietmar Goldbeck goldbeck at e-trend.de
Thu Aug 10 00:51:44 EDT 2006


  Hello,

if i run racluster with -S 127.0.0.1 it crashes after a few minutes.

racluster[12903]: 08-09-06 21:13:38.830670 ArgusRemoveFromQueue(0x81a80a0, 0x81cca20) obj not in queue

This is Racluster Version 3.0.0.rc.15 on Debian.
Commandline is

/usr/local/argus-3.0.0.rc.14/bin/racluster -nz -f /etc/tux-misst/racluster.conf -s stime ltime proto saddr sport daddr dport spkts dpkts -S 127.0.0.1

and racluster.conf has only 3 lines:

filter="icmp" status=60 idle=60
filter="tcp or udp" model="saddr sport daddr proto dport" status=60 idle=30
filter="" model="saddr daddr proto" status=60 idle=60

I will compile a newer snapshot soon.

  regards 
        Dietmar

-- 
 Alles Gute / best wishes  
     Dietmar Goldbeck         E-Mail: dietmar.goldbeck at schotterweg.de
Reporter (to Mahatma Gandhi): Mr Gandhi, what do you think of Western
Civilization?  Gandhi: I think it would be a good idea.



More information about the argus mailing list