[Oisf-users] Can't start AF_PACKET in Workers mode?

Cooper F. Nelson cnelson at ucsd.edu
Mon Mar 28 20:25:19 UTC 2016


Ok I can confirm the issue Eric Lebond has mentioned, I'm seeing the
same thing in the logfile.

You can verify that AF_PACKET mode is enabled by searching for
'runmode-af-packet.c' in the suricata log file.

-Coop

On 3/28/2016 1:13 PM, Cloherty, Sean E wrote:
> This is what I use currently:
> 
> /usr/bin/suricata -c /etc/suricata/suricata.yaml --user=suri --group=suri -v --af-packet=ens1f1 --runmode=workers -D
> 
> -----Original Message-----
> From: Cooper F. Nelson [mailto:cnelson at ucsd.edu] 
> Sent: Monday, March 28, 2016 16:10 PM
> To: Cloherty, Sean E <scloherty at mitre.org>; oisf-users at lists.openinfosecfoundation.org
> Subject: Re: [Oisf-users] Can't start AF_PACKET in Workers mode?
> 
> What is the command line use use to start suricata?


-- 
Cooper Nelson
Network Security Analyst
UCSD ITS Security Team
cnelson at ucsd.edu x41042

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: OpenPGP digital signature
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20160328/dbb29038/attachment-0002.sig>


More information about the Oisf-users mailing list