Actions
Bug #732
closedUNIX Socket will stop processing pcaps if log drive becomes full
Status:
Closed
Priority:
Low
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:
Description
Potentially not an issue Suricata should be concerned with but if the drive being logged to becomes full then the processing of pcaps in the queue will halt and will not continue when more space becomes available.
In some run modes (real time capture, for example) then full disks would result in lost events but offline pcap reading modes could afford to wait for disk space to become free.
Actions