Support #2983
closedno modbus output
Description
in pcap offline mode,like suricata -c /etc/suricata/suricata.yaml -r modbus.pcap.There is no thing if I use 'printf' in app-layer-modbus.c.Do I need dispose the suricata.yaml?
Updated by Victor Julien over 5 years ago
- Tracker changed from Bug to Support
- Subject changed from in pcap offline mode to no modbus output
- Assignee deleted (
Victor Julien) - Target version deleted (
4.1.5)
Updated by Victor Julien over 5 years ago
Did you enable the modbus parser in your yaml? Did you check the packet checksums? Did you enable midstream in case the modbus sessions have no TCP 3whs, etc?
Updated by John Smith over 5 years ago
OK,Victor.As you say,I have changed the midstream to true;the parser to yes;the checksum to no.Then the modbus parser is ok in pcap offline mode. I also add a new parser for iec104 and the parser iec104 is ok in AF-Packet mode or NFQ mode,but there is no output in pcap offline mode.So should I do some others thins?
Updated by Victor Julien over 5 years ago
I have no idea why it doesn't work for pcaps. It will be hard to say without access to the parsers.
Updated by Andreas Herz over 5 years ago
- Assignee set to Community Ticket
- Target version set to Support