[Oisf-users] [Question] suricata test with pcap-file(After upgrading the suricata version(2.0.11 --> 3.2))

박경호 pgh5247 at naver.com
Thu Jan 12 01:48:24 UTC 2017


Hello all.
 
I sent you an email about one issue a few days ago.
The issue was that the results(aler messages in fast.log) were different whenever the suricata(version 2.0.11) was executed.
After upgrading the version from 2.0.11 to 3.2, I did the test again.
Unfortunately, alert messages were different whenever the suricata was run with same a pcap-file.
 
I think that alert-messages should be same, if it is used the same pcap file or files.
 
I didn't change the configure file(suricata.yaml) and pcap-file's size is 693MB.
(pc memory is 8GB, cpu is intel i5-4460, os is Ubuntu 16.06)
 
please explain to me about this situation.
 
-Kyungho


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20170112/11b5d126/attachment.html>


More information about the Oisf-users mailing list