SnortSnarf memory usage on large files

"Jason Falciola" <[email protected]> Sun, 2 Feb 2003 04:35:40 -0500
Newsgroups gmane.comp.security.ids.snort.snarf
Message-ID <[email protected]>
Greetings,

I've read through the archives of this list and whenever someone has 
problems with SnortSnarf consuming memory when processing "large" files, 
the answers seem to be along the lines of this snippet from 
<http://www.silicondefense.com/pipermail/snortsnarf-users/2002-March/000258.html>:

<snip>

+ The #1 thing you can do is add more physical memory (or run it on a 
machine with more RAM).  When you need to start using swap space, it 
takes alot more time to complete (though it will eventually complete 
unless you run out of swap space).

+ Run it on a machine with a faster CPU if possible.  Or a less-used CPU.

+ Break it into smaller files.  (Although you loose the benefit of 
seeing it all together.  But see a post I am planning to make.)

+ Have SnortSnarf exclude certain alerts from its processing using 
and input filter.  At present these are -minprio, -sipin, and -dipin.

</snip>

The problem is that many are faced with a scenario where the last 2 
suggestions aren't an option.  The SANS GCIA practical requires the 
processing of files that are in the range of 300 MB.  All alerts must be 
processed to give a thorough analysis.

A friend has run into problems processing these files on a dual PIII 1 GhZ 
machine w/ 1 Gig of RAM and 500 MB of swap space runing RH Linux 6.2.  I 
would have thought that this box would have enough resources to handle 
these files, but Snortsnarf quits with the message that it ran out of 
memory.  Perl is version 5.005_03 and kernel is 2.2.14-5.0smp #1.  I'm wondering if an upgrade would help, or if the same 
issues would arise.

I guess my fundamental question is whether Snortsnarf should die or just 
take a long time to run when processing large files.  I would have thought 
the latter, but maybe I'm wrong.  What cpu/mem requirements are there for 
processing 300 mb of snort log files, assuming the box isn't doing 
anything else?

Another interesting suggestion was from 
<http://www.silicondefense.com/pipermail/snortsnarf-users/2002-March/000261.html>, 
but I'm unclear on how to actually do this.  Any pointers?

"there were huge savings to be had in caching dns answers (if you use that 
option), and especially in storing and sorting the alert lists."

Thanks!

Jason Falciola
Information Security Analyst
IBM Managed Security Services
[email protected]