Actions
Bug #1043
closedDifferent results for the same input pcap file in autofp mode
Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:
Description
I run suricata-1.4.6 with the same pcap file for two times and the outputs are not equal. Actually, I compare fast.log outputs and while the number of lines are equal, some lines which are in first fast.log output don't appear in the second one and vice versa. Specifically, the run mode was autofp; and I removed time stamps from all output lines, sort them and compared them. Surprisingly, there are some IP's in each output which don't appear in other one.
The pcapfile with which I tested suricata is ctf08_1228495450_eth1 of https://ictf.cs.ucsb.edu/data/ictf2008/ctf08_traffic.tgz
I attached two fast.log output files.
Files
Actions