Bug #5332
closed
- Description updated (diff)
- Description updated (diff)
- Status changed from New to Assigned
- Assignee changed from Victor Julien to Philippe Antoine
- Priority changed from High to Normal
- Target version changed from TBD to 7.0.0-beta1
Philippe could you have a look at what is going on here?
I do not reproduce the problem on latest master :
./src/suricata -l log -k none -r /Users/catena/Downloads/smb_store_error.pcap -c suricata.yaml --set stream.midstream=true --set vlan.use-for-tracking=false --set outputs.0.file-store.enabled=yes -S smb.rules
with smb.rules being alert smb any any -> any any (msg:"test filestore required"; filestore; sid:10; rev:1;)
Then
find log/filestore/ -type f
gives me log/filestore//d5/d50ea1b6b3e8ed084afc47537dd3dc0a5397d7f57595a9268c56c80e88095eee
Did you --set vlan.use-for-tracking=false
and enable filestore output ?
- Status changed from Assigned to Feedback
- Assignee changed from Philippe Antoine to yida zhang
- Target version changed from 7.0.0-beta1 to TBD
- Status changed from Feedback to Closed
Working as expected with --set vlan.use-for-tracking=false
Also available in: Atom
PDF