Actions
Documentation #5891
openuserguide: explain different log save directory in offline mode
Affected Versions:
Effort:
Difficulty:
Label:
Description
To prevent conflicts in the logs, when reading from a pcap (offline mode), Suri will save the logs to the current directory.
This is counter-intuitive and as far as I could see, not documented anywhere.
I saw this presented as a bug of sorts in https://stackoverflow.com/questions/61132410/how-to-run-suricata-on-pcap-mode-and-get-results-in-fast-log/67525274#67525274
Updated by Juliana Fajardini Reichow almost 2 years ago
- Description updated (diff)
Updated by Juliana Fajardini Reichow over 1 year ago
- Status changed from New to Assigned
Updated by Juliana Fajardini Reichow over 1 year ago
- Target version changed from 7.0.0 to 7.0.1
Updated by Juliana Fajardini Reichow over 1 year ago
- Target version changed from 7.0.1 to 7.0.2
Updated by Victor Julien about 1 year ago
- Target version changed from 7.0.2 to 7.0.3
Updated by Victor Julien about 1 year ago
- Target version changed from 7.0.3 to 8.0.0-beta1
Updated by Victor Julien 6 months ago
- Assignee changed from Juliana Fajardini Reichow to OISF Dev
Actions