# cannot create working directory

**URL:** <https://community.zeek.org/t/cannot-create-working-directory/2680>\
**Category:** Zeek\
**Created:** [May 23, 2013, 9:16pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680 "2013-05-23T21:16:36Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Richards\_James\_L\_DOA](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Richards\_James\_L\_DOA](https://community.zeek.org/u/Richards_James_L_DOA)\
**Post date:** [May 23, 2013, 9:16pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/1 "2013-05-23T21:16:36Z")

</div>

Good afternoon,

I am new to Bro, and have been trying to google around for some information, I am hoping one of you may have run into this before.

Our bro system stopped updating a bit ago, and when I go into the manager console and attempt to start things up, I get a cannot create working directory error messages for the nodes.

Have any of you run into this? It looks like it should be fairly straight forward, but I am very new to the system, and the specific installation of it.

Jim

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [May 23, 2013, 9:23pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/2 "2013-05-23T21:23:37Z")

</div>

First guess, full file system. Linux?

df -h

should get you space available numbers.

James

---

<div class="post-metadata">

**Author:** ![Schoenefeld\_Keith\_P](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@Schoenefeld\_Keith\_P](https://community.zeek.org/u/Schoenefeld_Keith_P)\
**Post date:** [May 23, 2013, 9:25pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/3 "2013-05-23T21:25:57Z")

</div>

Are you running commands as the correct user?

– KS

---

<div class="post-metadata">

**Author:** ![Richards\_James\_L\_DOA](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Richards\_James\_L\_DOA](https://community.zeek.org/u/Richards_James_L_DOA)\
**Post date:** [May 23, 2013, 9:31pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/4 "2013-05-23T21:31:08Z")

</div>

I am checking that out, because that would make perfect sense.

Thanks much!

---

<div class="post-metadata">

**Author:** ![Richards\_James\_L\_DOA](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Richards\_James\_L\_DOA](https://community.zeek.org/u/Richards_James_L_DOA)\
**Post date:** [May 24, 2013, 7:46pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/5 "2013-05-24T19:46:21Z")

</div>

Well...

&nbsp;&nbsp;It doesn't look like a permissions issue, all files are bro:bro, and the broctl.sh script looks to be running as bro.

Plenty of space on the drives.

It has been suggested that I take this as an opportunity to install the latest version of bro on the nodes. I have a couple of questions:

On Ubuntu, can I run the command to install the binaries, is this recommended, or should I compile, any advantage/risk to either method?

Do I need to update the brocntl machine as well, that one is running more than just Bro so I cannot take it down at will.

Thanks much,

Jim

---

<div class="post-metadata">

**Author:** ![Warren\_Raquel](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@Warren\_Raquel](https://community.zeek.org/u/Warren_Raquel)\
**Post date:** [May 24, 2013, 7:48pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/6 "2013-05-24T19:48:43Z")

</div>

You're not out of inodes are you?

df -i

- -Warren

> Well...
> 
> It doesn't look like a permissions issue, all files are bro:bro,  
> and the broctl.sh script looks to be running as bro.
> 
> Plenty of space on the drives.
> 
> It has been suggested that I take this as an opportunity to install  
> the latest version of bro on the nodes. I have a couple of  
> questions:
> 
> On Ubuntu, can I run the command to install the binaries, is this  
> recommended, or should I compile, any advantage/risk to either  
> method?
> 
> Do I need to update the brocntl machine as well, that one is  
> running more than just Bro so I cannot take it down at will.
> 
> Thanks much,
> 
> Jim
> 
> [mailto:bro-bounces@bro.org] On Behalf Of James Lay Sent: Thursday,  
> May 23, 2013 4:24 PM To: bro@bro.org Subject: Re: [Bro] cannot  
> create working directory
> 
> > Good afternoon,
> > 
> > I am new to Bro, and have been trying to google around for some  
> > information, I am hoping one of you may have run into this  
> > before.
> > 
> > Our bro system stopped updating a bit ago, and when I go into the  
> > manager console and attempt to start things up, I get a cannot  
> > create working directory error messages for the nodes.
> > 
> > Have any of you run into this? It looks like it should be fairly  
> > straight forward, but I am very new to the system, and the  
> > specific installation of it.
> > 
> > Jim
> 
> First guess, full file system. Linux?
> 
> df -h
> 
> should get you space available numbers.
> 
> James \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Bro mailing  
> list bro@bro-ids.org  
> [mailman.icsi.berkeley.edu Mailing Lists](http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/bro)
> 
> \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Bro mailing list  
> bro@bro-ids.org  
> [mailman.icsi.berkeley.edu Mailing Lists](http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/bro)

- --  
Warren Raquel \<wraquel@illinois.edu\>  
Incident Response and Security Team Lead  
National Center for Supercomputing Applications  
+1 (217) 333-2876  
PGP Fingerprint:  
F88E 960B 6193 A3ED 0BB2  
45C7 7DF9 57DB 6DCF 34C1

---

<div class="post-metadata">

**Author:** ![Daniel\_Thayer](https://avatars.discourse-cdn.com/v4/letter/d/8dc957/32.png) [@Daniel\_Thayer](https://community.zeek.org/u/Daniel_Thayer)\
**Post date:** [May 24, 2013, 8:06pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/7 "2013-05-24T20:06:00Z")

</div>

Are you getting the error message for only one node,  
or more than one?

Did you verify that you can connect to the affected nodes,  
and that each node has plenty of free disk space? You  
could try (make sure you get output from every node): "broctl df"

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@Azoff\_Justin](https://community.zeek.org/u/Azoff_Justin)\
**Post date:** [May 24, 2013, 9:03pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/8 "2013-05-24T21:03:15Z")

</div>

Have you tried this?

&nbsp;&nbsp;&nbsp;&nbsp;broctl stop  
&nbsp;&nbsp;&nbsp;&nbsp;broctl cleanup  
&nbsp;&nbsp;&nbsp;&nbsp;broctl install  
&nbsp;&nbsp;&nbsp;&nbsp;broctl check  
&nbsp;&nbsp;&nbsp;&nbsp;broctl restart

Apparently that error comes from "mkdir -p" failing to make the spool  
directory.

You can find what that is by running

&nbsp;&nbsp;&nbsp;&nbsp;broctl config | grep spooldir

so for whatever reason it failing(or at least thinking it is failing) to  
mkdir -p spooldir/worker-name. cleanup+install may fix things though (  
unless you are really out of inodes)

broctl doesn't show stderr from the mkdir command, so logging into the  
worker node and running mkdir -p manually might conclusively show why  
this isn't working.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/cannot-create-working-directory/2680/9 "2022-05-06T15:40:59Z")

</div>


