pf reinstall:
Reading package lists...
Building dependency tree...
Reading state information...
0 upgraded, 0 newly installed, 1 reinstalled, 0 to remove and 0 not upgraded.
Need to get 0 B/87.5 kB of archives.
After this operation, 0 B of additional disk space will be used.
(Reading database ... 87757 files and directories currently installed.)
Preparing to unpack .../securityonion-pfring-module_20121107-0ubuntu0securityonion28_all.deb
...
Stopping: HIDS
* stopping: ossec_agent (sguil) [ OK ]
Stopping: Bro
stopping vps90275.vps.ovh.ca-tun0-1 ...
stopping proxy ...
stopping manager ...
Stopping: vps90275.vps.ovh.ca-tun0
* stopping: snort_agent (sguil) [ OK ]
* stopping: suricata (alert data) (not running) [ WARN ]
- stale PID file found, deleting!
* stopping: barnyard2 (spooler, unified2 format) [ OK ]
Waiting up to 30 seconds for processes to terminate gracefully.
Removing pf_ring from /etc/modules...done.
Attempting to remove pf_ring from running kernel...done.
Removing pf_ring from DKMS...done.
Unpacking securityonion-pfring-module (20121107-0ubuntu0securityonion28) over (20121107-0ubun
tu0securityonion28) ...
Setting up securityonion-pfring-module (20121107-0ubuntu0securityonion28) ...
Loading new pf_ring-6 DKMS files...
First Installation: checking all kernels...
Building only for 3.13.0-92-generic
Building for architecture x86_64
Building initial module for 3.13.0-92-generic
Done.
pf_ring:
Running module version sanity check.
- Original module
- No original module exists within this kernel
- Installation
- Installing to /lib/modules/3.13.0-92-generic/updates/dkms/
depmod....
DKMS: install completed.
Starting: HIDS
* starting: ossec_agent (sguil) [ OK ]
Starting: Bro
removing old policies in /nsm/bro/spool/installed-scripts-do-not-touch/site ...
removing old policies in /nsm/bro/spool/installed-scripts-do-not-touch/auto ...
creating policy directories ...
installing site policies ...
generating cluster-layout.bro ...
generating local-networks.bro ...
generating broctl-config.bro ...
generating broctl-config.sh ...
updating nodes ...
starting manager ...
starting proxy ...
starting vps90275.vps.ovh.ca-tun0-1 ...
Starting: vps90275.vps.ovh.ca-tun0
* starting: snort_agent (sguil) [ OK ]
* starting: suricata (alert data) [ OK ]
* starting: barnyard2 (spooler, unified2 format) [ OK ]
soup:
###########################################################################
This script will automatically install all available updates
and remove any old kernels (keeping at least two kernels).
For distributed deployments, please ensure this script is
run on the master server before updating sensors.
If mysql-server updates are available, it will stop sensor processes
to ensure a clean update.
At the end of the script, if mysql-server and/or kernel updates
were installed, you will be prompted to reboot.
###########################################################################
Press Enter to continue or Ctrl-C to cancel.
Checking for kernels that can be removed...
No kernels are eligible for removal
Checking for updates...
Reading package lists... Done
Building dependency tree
Reading state information... Done
securityonion-pfring-module is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Reading package lists... Done
Building dependency tree
Reading state information... Done
Calculating upgrade... Done
0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
###########################################################################
All updates have been installed.
uname -a : 3.13.0-92-generic #139-Ubuntu SMP Tue Jun 28 20:42:26 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
and * starting: suricata (alert data) fails 2 mins later......
Since I can get no furthr help, does anyone know a stable kernel version that works with latest pfring?
Sorry for the late response.
Have you tried reverting to a previous OS kernel and seeing if it helps any? I wouldn't think it would matter, as I hadn't heard of anyone having issues with this particular kernel, but it may help.
Thanks,
Wes
As per your suggestion, I have started a new thread.
Regards,
Strix