Project

General

Profile

Actions

Bug #3361

closed

json log files are not recreated if files are deleted

Added by corey thomas over 5 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:

Description

If a file, say alert.json, is deleted and Suricata is not restarted the old file is still written to on disk.
This causes other programs that are looking for the file to fail, sometimes silently.

It is normal Linux behavior (Oracle Linux in this case) but it would be great if Suricata handled the file deletion and started writing a new file.
Even better if the file was recovered from after deletion time (dtime of inode).

Actions

Also available in: Atom PDF