Project

General

Profile

Support #2801

Disable/Enable suricata logs on a running instance

Added by Pavan P 2 months ago. Updated about 2 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
medium
Label:

Description

Hi,

I tried to disable/enable suricata logs ie fast.log,eve.log,stats.log on a running suricata instance by sending "kill -USR2 <pid_suricata>" signal after updating the yaml file. But, i observe that the changes in the yaml file are not reflected. The log disable/enable did not happen.

Could you please let me know if it is supported. If yes, how would i achieve it

Thanks
Pavan

History

#1

Updated by Victor Julien 2 months ago

  • Priority changed from Immediate to Normal

This is not supported at this time. The USR2 signal will reload the rules only. Log output cannot dynamically be enabled/disabled.

#2

Updated by Victor Julien about 2 months ago

  • Status changed from New to Closed

Also available in: Atom PDF