Project

General

Profile

Actions

Documentation #5891

open

userguide: explain different log save directory in offline mode

Added by Juliana Fajardini Reichow almost 2 years ago. Updated 6 months ago.

Status:
Assigned
Priority:
Low
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

To prevent conflicts in the logs, when reading from a pcap (offline mode), Suri will save the logs to the current directory.

This is counter-intuitive and as far as I could see, not documented anywhere.

I saw this presented as a bug of sorts in https://stackoverflow.com/questions/61132410/how-to-run-suricata-on-pcap-mode-and-get-results-in-fast-log/67525274#67525274

Actions

Also available in: Atom PDF