[Oisf-users] Suricata not writing to unified2

Peter Manev petermanev at gmail.com
Fri Nov 27 22:38:11 UTC 2015


On Fri, Nov 27, 2015 at 9:53 PM, Brian Hennigar <bhennigar at gmail.com> wrote:
> I've upgraded to suricata 2.0.10 today and since the upgrade, Suricata is
> not writing to the unified2.alert file.
> It creates the file when it starts however the file size stays at 0. The
> alert-debug.log file does not change either.
>
> The system is Ubuntu server 14.04 x64. I used apt-get upgrade to install the
> lastest stable release.
>
> What I can try to get the alerts to write?  Everything was working before
> the upgrade. The process stays running once started.

Do you have alerts in fast.log?

>
>
> Thanks,
> Brian
>
> _______________________________________________
> Suricata IDS Users mailing list: oisf-users at openinfosecfoundation.org
> Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
> List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
> Suricata User Conference November 4 & 5 in Barcelona: http://oisfevents.net



-- 
Regards,
Peter Manev



More information about the Oisf-users mailing list