[Oisf-users] Suricata not writing to unified2

Brian Hennigar bhennigar at gmail.com
Fri Nov 27 23:23:47 UTC 2015


No, that file is empty.

On Fri, Nov 27, 2015 at 6:38 PM, Peter Manev <petermanev at gmail.com> wrote:

> On Fri, Nov 27, 2015 at 9:53 PM, Brian Hennigar <bhennigar at gmail.com>
> wrote:
> > I've upgraded to suricata 2.0.10 today and since the upgrade, Suricata is
> > not writing to the unified2.alert file.
> > It creates the file when it starts however the file size stays at 0. The
> > alert-debug.log file does not change either.
> >
> > The system is Ubuntu server 14.04 x64. I used apt-get upgrade to install
> the
> > lastest stable release.
> >
> > What I can try to get the alerts to write?  Everything was working before
> > the upgrade. The process stays running once started.
>
> Do you have alerts in fast.log?
>
> >
> >
> > Thanks,
> > Brian
> >
> > _______________________________________________
> > Suricata IDS Users mailing list: oisf-users at openinfosecfoundation.org
> > Site: http://suricata-ids.org | Support:
> http://suricata-ids.org/support/
> > List:
> https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
> > Suricata User Conference November 4 & 5 in Barcelona:
> http://oisfevents.net
>
>
>
> --
> Regards,
> Peter Manev
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20151127/fec8180d/attachment-0002.html>


More information about the Oisf-users mailing list