Project

General

Profile

Actions

Bug #7024

open

unix-socket: inconsistent default behavior

Added by Victor Julien 4 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

In the default config, we have

unix-command:
  enabled: auto

At least on Linux, this leads to the suricata run directory being created as well as the socket being opened.

However, if this section is omitted from a yaml, the behavior is to disable the unix socket.

I believe omitting the setting from the yaml should act as if unix-command.enabled=auto was set.

No data to display

Actions

Also available in: Atom PDF