2014:11:18-10:35:52 seth-2 snort[31725]: S5: Session exceeded configured max segs to queue 2621 using 2621 segs (server queue). 10.1.30.100 56154 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-10:40:08 seth-2 snort[31726]: S5: Session exceeded configured max bytes to queue 1048576 using 1048601 bytes (server queue). 10.1.20.44 38178 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-10:41:12 seth-2 snort[31726]: S5: Session exceeded configured max segs to queue 2621 using 2621 segs (server queue). 10.1.20.42 37790 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-10:41:12 seth-2 snort[31725]: S5: Session exceeded configured max segs to queue 2621 using 2621 segs (server queue). 10.1.20.41 51980 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-10:41:54 seth-2 snort[31726]: S5: Session exceeded configured max bytes to queue 1048576 using 1048760 bytes (server queue). 10.1.20.45 43635 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-10:42:58 seth-2 snort[31726]: S5: Session exceeded configured max bytes to queue 1048576 using 1048863 bytes (server queue). 10.1.20.43 58492 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-10:44:11 seth-2 snort[31725]: S5: Session exceeded configured max segs to queue 2621 using 2621 segs (server queue). 10.1.30.11 34181 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:28:25 seth-2 snort[31726]: S5: Pruned 5 sessions from cache for memcap. 48 scbs remain. memcap: 8405960/8388608
2014:11:18-11:28:25 seth-2 snort[31726]: S5: Pruned 5 sessions from cache for memcap. 43 scbs remain. memcap: 8409743/8388608
2014:11:18-11:28:25 seth-2 snort[31726]: S5: Pruned 5 sessions from cache for memcap. 38 scbs remain. memcap: 8422173/8388608
2014:11:18-11:28:25 seth-2 snort[31726]: S5: Pruned session from cache that was using 1123571 bytes (memcap/check). 10.1.20.44 38178 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:28:25 seth-2 snort[31726]: S5: Pruned 3 sessions from cache for memcap. 35 scbs remain. memcap: 7302513/8388608
2014:11:18-11:35:03 seth-2 snort[31725]: S5: Session exceeded configured max bytes to queue 1048576 using 1048737 bytes (server queue). 10.1.20.38 37328 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:39:02 seth-2 snort[31726]: S5: Session exceeded configured max bytes to queue 1048576 using 1048843 bytes (server queue). 10.1.20.40 50447 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:39:02 seth-2 snort[31726]: S5: Session exceeded configured max bytes to queue 1048576 using 1048754 bytes (server queue). 10.1.20.39 34340 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:39:53 seth-2 snort[31726]: S5: Pruned session from cache that was using 1114850 bytes (stale/timeout). 10.1.20.39 34340 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:39:53 seth-2 snort[31726]: S5: Pruned session from cache that was using 1115857 bytes (stale/timeout). 10.1.20.40 50447 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
2014:11:18-11:43:03 seth-2 snort[31726]: S5: Session exceeded configured max segs to queue 2621 using 2621 segs (server queue). 10.1.20.46 46653 --> 10.1.10.20 514 (0) : LWstate 0x40 LWFlags 0x2101
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
can you please provide that patch here? otherwise it take ages to a support case to be answered :/
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
I opened up a case for this yesterday and also included a link to this thread. They seemed to be well aware of the issue as the tech said he was advised of the problem when he started his shift.
Here is the case update response I received this morning.
"Just wanted to update you that the case is being investigated by Global Escalations Team, once an update/patch exists, i will inform you.
Thank you again for your patience"
If this is just some incorrect snort rules, why would a firmware update be necessary?
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.