Project

General

Profile

Actions

Documentation #5891

open

userguide: explain different log save directory in offline mode

Added by Juliana Fajardini Reichow about 1 year ago. Updated 4 months ago.

Status:
Assigned
Priority:
Low
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

To prevent conflicts in the logs, when reading from a pcap (offline mode), Suri will save the logs to the current directory.

This is counter-intuitive and as far as I could see, not documented anywhere.

I saw this presented as a bug of sorts in https://stackoverflow.com/questions/61132410/how-to-run-suricata-on-pcap-mode-and-get-results-in-fast-log/67525274#67525274

Actions #1

Updated by Juliana Fajardini Reichow about 1 year ago

  • Description updated (diff)
Actions #2

Updated by Juliana Fajardini Reichow 10 months ago

  • Status changed from New to Assigned
Actions #3

Updated by Victor Julien 10 months ago

  • Priority changed from Normal to Low
Actions #4

Updated by Juliana Fajardini Reichow 9 months ago

  • Target version changed from 7.0.0 to 7.0.1
Actions #5

Updated by Juliana Fajardini Reichow 7 months ago

  • Target version changed from 7.0.1 to 7.0.2
Actions #6

Updated by Victor Julien 6 months ago

  • Target version changed from 7.0.2 to 7.0.3
Actions #7

Updated by Victor Julien 4 months ago

  • Target version changed from 7.0.3 to 8.0.0-beta1
Actions

Also available in: Atom PDF