Project

General

Profile

Actions

Support #2396

closed

I enabled http-log setting, but got an empty http-log.log

Added by wangtao wang over 6 years ago. Updated about 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

My suricata.yml file is here.

The network fundation like this
!!


Files

suricata.yaml (66.4 KB) suricata.yaml wangtao wang, 12/27/2017 04:14 AM
架构.png (155 KB) 架构.png wangtao wang, 12/27/2017 05:32 AM
result.pcap (984 KB) result.pcap .pcap wangtao wang, 01/02/2018 02:43 AM
suricataconf.png (373 KB) suricataconf.png suricata configuration wangtao wang, 01/02/2018 02:44 AM
Actions #1

Updated by wangtao wang over 6 years ago

!!

Actions #2

Updated by wangtao wang over 6 years ago

and I run the cmd like this:
./suricata -i eth3

Actions #3

Updated by Andreas Herz over 6 years ago

  • Assignee set to Anonymous
  • Target version set to Support

What version are you running?
Can you provide a .pcap with some testing traffic?
Without more details it's hard to tell what the issue may be.

Updated by wangtao wang over 6 years ago

Andreas Herz wrote:

What version are you running?
Can you provide a .pcap with some testing traffic?
Without more details it's hard to tell what the issue may be.

Suricata 4.0.3
The testing traffic file is here.
Suricata's detail configuration like this

Actions #5

Updated by wangtao wang over 6 years ago

Andreas Herz wrote:

What version are you running?
Can you provide a .pcap with some testing traffic?
Without more details it's hard to tell what the issue may be.

There is a configuration about vlan:

  1. This option controls the use of vlan ids in the flow (and defrag)
  2. hashing. Normally this should be enabled, but in some (broken)
  3. setups where both sides of a flow are not tagged with the same vlan
  4. tag, we can ignore the vlan id's in the flow hashing.
    vlan:
    use-for-tracking: false

When set the user-for-tracking to false, the http-log works!

Actions #6

Updated by Andreas Herz over 6 years ago

so it's solved for you now?

Actions #7

Updated by Victor Julien about 5 years ago

  • Status changed from New to Closed
  • Assignee deleted (Anonymous)
  • Target version deleted (Support)
Actions

Also available in: Atom PDF