Project

General

Profile

Actions

Support #2990

closed

files-json.log is empty

Added by Anh Pham almost 5 years ago. Updated over 4 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Affected Versions:
Label:

Description

I use suricata 4.0.4 and in suricata.yaml, i edited fast.log and files-json.log to enabled:yes - append:yes. But when I cat fast.log and files-json.log, files-json.log is empty.

Actions #1

Updated by Anh Pham almost 5 years ago

I use suricata 4.0.4 and in suricata.yaml, i edited fast.log and files-json.log to enabled:yes - append:yes. But when I cat fast.log and files-json.log, files-json.log is empty.

Is there any way to solve this problem? Thank you very much.

Actions #2

Updated by Victor Julien almost 5 years ago

  • Tracker changed from Bug to Support
Actions #3

Updated by Peter Manev almost 5 years ago

I would recommend using latest stable Suricata - 4.1.4 and eve.json (instead of fast.log and files log as these are legacy).
After it is up and running , check if Suricata starts properly , if there are no errors , if you have defined your networks correctly.

Actions #4

Updated by Andreas Herz almost 5 years ago

  • Status changed from New to Feedback
  • Assignee set to Anh Pham
  • Target version set to Support

Can you also add the configuration file so we can check for any issues there?

Actions #5

Updated by Victor Julien over 4 years ago

  • Status changed from Feedback to Closed
Actions

Also available in: Atom PDF