Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- training@SuricataThreatHunting:~$ ls -l
- total 80
- drwxr-xr-x 2 training training 4096 Mar 12 22:21 Desktop
- drwxr-xr-x 2 training training 4096 Dec 27 16:10 Documents
- drwxr-xr-x 2 training training 4096 Mar 18 22:12 Downloads
- -rw-r--r-- 1 training training 35147 Jul 16 2018 LICENSE
- drwxr-xr-x 2 training training 4096 Dec 27 16:10 Public
- drwxr-xr-x 2 training training 4096 Dec 27 16:10 Videos
- drwxr-xr-x 7 training training 4096 Mar 21 20:39 exercises
- -rwxr-xr-x 1 training training 705 Dec 27 20:59 reset_dashboards.sh
- -rw-r--r-- 1 training training 544 Feb 9 21:13 sigdev.rules
- drwxr-xr-x 2 training training 4096 Apr 10 22:15 slides
- -rwxr-xr-x 1 training training 2461 May 19 03:00 suri.sh
- drwxr-xr-x 2 root root 4096 May 17 08:38 vmexportprep
- training@SuricataThreatHunting:~$ ls -l /var/log/suricata/
- total 16
- drwxr-xr-x 2 logstash logstash 4096 Dec 16 21:15 StatsByDate
- drwxr-xr-x 2 logstash logstash 4096 Dec 13 16:36 certs
- drwxr-xr-x 2 logstash logstash 4096 Dec 13 16:36 core
- drwxr-xr-x 2 logstash logstash 4096 Dec 13 16:36 files
- training@SuricataThreatHunting:~$ sudo ./suri.sh ./exercises/pcaps/eod_exercise-1.pcap
- ingesting into moloch with tag eod_exercise-1.pcap
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:255) <Info> (ConfYamlParse) -- Including configuration file /etc/suricata/selks5-addin.yaml.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'default-rule-path' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'rule-files' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'classification-file' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'reference-config-file' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'detect' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'default-log-dir' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'stats' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'outputs' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'logging' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'app-layer' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'asn1-max-frames' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:255) <Info> (ConfYamlParse) -- Including configuration file /etc/suricata/selks5-interfaces-config.yaml.
- [9308] 19/5/2019 -- 03:10:04 - (conf-yaml-loader.c:279) <Info> (ConfYamlParse) -- Configuration node 'af-packet' redefined.
- [9308] 19/5/2019 -- 03:10:04 - (suricata.c:1067) <Notice> (LogVersion) -- This is Suricata version 5.0.0-dev (rev cc492c50c) running in USER mode
- [9308] 19/5/2019 -- 03:10:04 - (util-cpu.c:171) <Info> (UtilCpuPrintSummary) -- CPUs/cores online: 2
- [9308] 19/5/2019 -- 03:10:04 - (util-luajit.c:98) <Config> (LuajitSetupStatesPool) -- luajit states preallocated: 128
- [9308] 19/5/2019 -- 03:10:04 - (app-layer-htp.c:2329) <Config> (HTPConfigSetDefaultsPhase2) -- 'default' server has 'request-body-minimal-inspect-size' set to 33981 and 'request-body-inspect-window' set to 4191 after randomization.
- [9308] 19/5/2019 -- 03:10:04 - (app-layer-htp.c:2347) <Config> (HTPConfigSetDefaultsPhase2) -- 'default' server has 'response-body-minimal-inspect-size' set to 41368 and 'response-body-inspect-window' set to 15834 after randomization.
- [9308] 19/5/2019 -- 03:10:04 - (app-layer-smb.c:337) <Config> (RegisterSMBParsers) -- SMB stream depth: 0
- [9308] 19/5/2019 -- 03:10:04 - (app-layer-modbus.c:1503) <Config> (RegisterModbusParsers) -- Modbus request flood protection level: 500
- [9308] 19/5/2019 -- 03:10:04 - (app-layer-modbus.c:1514) <Config> (RegisterModbusParsers) -- Modbus stream depth: 0
- [9308] 19/5/2019 -- 03:10:04 - (app-layer-dnp3.c:1628) <Config> (RegisterDNP3Parsers) -- Registering DNP3/tcp parsers.
- [9308] 19/5/2019 -- 03:10:04 - (host.c:254) <Config> (HostInitConfig) -- allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64
- [9308] 19/5/2019 -- 03:10:04 - (host.c:277) <Config> (HostInitConfig) -- preallocated 1000 hosts of size 136
- [9308] 19/5/2019 -- 03:10:04 - (host.c:279) <Config> (HostInitConfig) -- host memory usage: 398144 bytes, maximum: 33554432
- [9308] 19/5/2019 -- 03:10:04 - (util-coredump-config.c:129) <Config> (CoredumpLoadConfig) -- Core dump size set to unlimited.
- [9308] 19/5/2019 -- 03:10:04 - (defrag-hash.c:248) <Config> (DefragInitConfig) -- allocated 3670016 bytes of memory for the defrag hash... 65536 buckets of size 56
- [9308] 19/5/2019 -- 03:10:04 - (defrag-hash.c:273) <Config> (DefragInitConfig) -- preallocated 65535 defrag trackers of size 160
- [9308] 19/5/2019 -- 03:10:04 - (defrag-hash.c:280) <Config> (DefragInitConfig) -- defrag memory usage: 14155616 bytes, maximum: 33554432
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:399) <Config> (StreamTcpInitConfig) -- stream "prealloc-sessions": 2048 (per thread)
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:418) <Config> (StreamTcpInitConfig) -- stream "memcap": 67108864
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:424) <Config> (StreamTcpInitConfig) -- stream "midstream" session pickups: disabled
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:430) <Config> (StreamTcpInitConfig) -- stream "async-oneside": disabled
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:447) <Config> (StreamTcpInitConfig) -- stream "checksum-validation": disabled
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:475) <Config> (StreamTcpInitConfig) -- stream."inline": disabled
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:488) <Config> (StreamTcpInitConfig) -- stream "bypass": disabled
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:510) <Config> (StreamTcpInitConfig) -- stream "max-synack-queued": 5
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:532) <Config> (StreamTcpInitConfig) -- stream.reassembly "memcap": 268435456
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:550) <Config> (StreamTcpInitConfig) -- stream.reassembly "depth": 1048576
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:626) <Config> (StreamTcpInitConfig) -- stream.reassembly "toserver-chunk-size": 2587
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:628) <Config> (StreamTcpInitConfig) -- stream.reassembly "toclient-chunk-size": 2508
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp.c:640) <Config> (StreamTcpInitConfig) -- stream.reassembly.raw: enabled
- [9308] 19/5/2019 -- 03:10:04 - (stream-tcp-reassemble.c:373) <Config> (StreamTcpReassemblyConfig) -- stream.reassembly "segment-prealloc": 2048
- [9308] 19/5/2019 -- 03:10:04 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- eve-log output device (regular) initialized: eve.json
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'alert'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'flow'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'http'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dns'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tls'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'files'
- [9308] 19/5/2019 -- 03:10:04 - (output-json-file.c:370) <Config> (OutputFileLogInitSub) -- forcing magic lookup for logged files
- [9308] 19/5/2019 -- 03:10:04 - (util-file.c:190) <Config> (FileForceHashParseCfg) -- forcing md5 calculation for logged or stored files
- [9308] 19/5/2019 -- 03:10:04 - (util-file.c:199) <Config> (FileForceHashParseCfg) -- forcing sha1 calculation for logged or stored files
- [9308] 19/5/2019 -- 03:10:04 - (util-file.c:208) <Config> (FileForceHashParseCfg) -- forcing sha256 calculation for logged or stored files
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smtp'
- [9308] 19/5/2019 -- 03:10:04 - (output-json-email-common.c:455) <Info> (OutputEmailInitConf) -- Going to log the md5 sum of email body
- [9308] 19/5/2019 -- 03:10:04 - (output-json-email-common.c:459) <Info> (OutputEmailInitConf) -- Going to log the md5 sum of email subject
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ssh'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dnp3'
- [9308] 19/5/2019 -- 03:10:04 - (output-json-dnp3.c:392) <Info> (OutputDNP3LogInitSub) -- DNP3 log sub-module initialized.
- [9308] 19/5/2019 -- 03:10:04 - (output-json-dnp3.c:392) <Info> (OutputDNP3LogInitSub) -- DNP3 log sub-module initialized.
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'nfs'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smb'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tftp'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ikev2'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'krb5'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dhcp'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'stats'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'flow'
- [9308] 19/5/2019 -- 03:10:04 - (runmodes.c:626) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'metadata'
- [9308] 19/5/2019 -- 03:10:04 - (log-pcap.c:1312) <Info> (PcapLogInitCtx) -- Using log dir /data/nsm/
- [9308] 19/5/2019 -- 03:10:04 - (log-pcap.c:1423) <Info> (PcapLogInitCtx) -- Selected pcap-log compression method: (null)
- [9308] 19/5/2019 -- 03:10:04 - (log-pcap.c:1427) <Info> (PcapLogInitCtx) -- using multi logging
- [9308] 19/5/2019 -- 03:10:04 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- stats output device (regular) initialized: stats.log
- [9308] 19/5/2019 -- 03:10:04 - (suricata.c:2410) <Config> (SetupDelayedDetect) -- Delayed detect disabled
- [9308] 19/5/2019 -- 03:10:04 - (detect-engine.c:1589) <Config> (DetectEngineCtxInitReal) -- pattern matchers: MPM: hs, SPM: hs
- [9308] 19/5/2019 -- 03:10:04 - (detect-engine.c:1987) <Config> (DetectEngineCtxLoadConf) -- grouping: tcp-whitelist 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080
- [9308] 19/5/2019 -- 03:10:04 - (detect-engine.c:2011) <Config> (DetectEngineCtxLoadConf) -- grouping: udp-whitelist 53, 135, 5060
- [9308] 19/5/2019 -- 03:10:04 - (detect-engine.c:2045) <Config> (DetectEngineCtxLoadConf) -- prefilter engines: MPM and keywords
- [9308] 19/5/2019 -- 03:10:04 - (reputation.c:639) <Info> (SRepInit) -- Loading reputation file: /etc/suricata/rules/scirius-iprep.list
- [9308] 19/5/2019 -- 03:10:04 - (host.c:294) <Perf> (HostPrintStats) -- host memory usage: 2254680 bytes, maximum: 33554432
- [9308] 19/5/2019 -- 03:10:04 - (detect-engine-loader.c:247) <Config> (ProcessSigFiles) -- Loading rule file: /etc/suricata/rules/scirius.rules
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-loader.c:247) <Config> (ProcessSigFiles) -- Loading rule file: /home/training/sigdev.rules
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-loader.c:336) <Config> (SigLoadSignatures) -- No rules loaded from /home/training/sigdev.rules
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-loader.c:351) <Info> (SigLoadSignatures) -- 2 rule files processed. 21144 rules successfully loaded, 0 rules failed
- [9308] 19/5/2019 -- 03:10:08 - (util-threshold-config.c:1126) <Info> (SCThresholdConfParseFile) -- Threshold config parsed: 0 rule(s) found
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:327) <Perf> (SetupBuiltinMpm) -- using shared mpm ctx' for tcp-packet
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:327) <Perf> (SetupBuiltinMpm) -- using shared mpm ctx' for tcp-stream
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:327) <Perf> (SetupBuiltinMpm) -- using shared mpm ctx' for udp-packet
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:327) <Perf> (SetupBuiltinMpm) -- using shared mpm ctx' for other-ip
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_uri
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_uri
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_request_line
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_client_body
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_response_line
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header_names
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header_names
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_accept
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_accept_enc
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_accept_lang
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_referer
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_connection
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_len
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_len
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_type
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_type
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http.server
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http.location
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_protocol
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_protocol
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_start
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_start
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_header
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_header
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_method
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_cookie
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_cookie
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.name
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file.magic
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_user_agent
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_host
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_host
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_stat_msg
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_stat_code
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dns_query
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dnp3_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dnp3_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls.sni
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls.cert_issuer
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls.cert_subject
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls.cert_serial
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls.cert_fingerprint
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ja3.hash
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ja3.string
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dce_stub_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dce_stub_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dce_stub_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dce_stub_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for smb_named_pipe
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for smb_share
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_protocol
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_protocol
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_software
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_software
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for krb5_cname
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-mpm.c:272) <Perf> (DetectMpmSetupAppMpms) -- using shared mpm ctx' for krb5_sname
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405000: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405001: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405002: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405003: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405004: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405005: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405006: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405007: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405008: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405009: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405010: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405011: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405012: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405013: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405014: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405015: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405016: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405017: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405018: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405019: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405020: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2405021: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2014385: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2014386: prefilter is on "flow"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2008542: prefilter is on "dsize"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2013506: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001219: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2002910: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2002911: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2003068: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2010935: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2010936: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2010937: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2010938: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2010939: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2102523: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2102523: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001569: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001579: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001580: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001581: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001582: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001583: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2001972: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2002992: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2002993: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2002994: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2002995: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1402) <Config> (SigAddressPrepareStage1) -- sid 2013479: prefilter is on "flags"
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1426) <Info> (SigAddressPrepareStage1) -- 21149 signatures processed. 13 are IP-only rules, 6321 are inspecting packet payload, 14754 inspect application layer, 0 are decoder event only
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1429) <Config> (SigAddressPrepareStage1) -- building signature grouping structure, stage 1: preprocessing rules... complete
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1266) <Perf> (RulesGroupByPorts) -- TCP toserver: 76 port groups, 60 unique SGH's, 16 copies
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1266) <Perf> (RulesGroupByPorts) -- TCP toclient: 76 port groups, 46 unique SGH's, 30 copies
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1266) <Perf> (RulesGroupByPorts) -- UDP toserver: 76 port groups, 44 unique SGH's, 32 copies
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1266) <Perf> (RulesGroupByPorts) -- UDP toclient: 45 port groups, 25 unique SGH's, 20 copies
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1012) <Perf> (RulesGroupByProto) -- OTHER toserver: 254 proto groups, 2 unique SGH's, 252 copies
- [9308] 19/5/2019 -- 03:10:08 - (detect-engine-build.c:1049) <Perf> (RulesGroupByProto) -- OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-build.c:1801) <Perf> (SigAddressPrepareStage4) -- Unique rule groups: 177
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "toserver TCP packet": 33
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "toclient TCP packet": 30
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "toserver TCP stream": 33
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "toclient TCP stream": 38
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "toserver UDP packet": 44
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "toclient UDP packet": 25
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:982) <Perf> (MpmStoreReportStats) -- Builtin MPM "other IP packet": 2
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_uri": 13
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_raw_uri": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_request_line": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_client_body": 5
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient http_response_line": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_header": 6
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient http_header": 4
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_header_names": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_accept": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_referer": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_content_len": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_content_type": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient http_content_type": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_start": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_raw_header": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient http_raw_header": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_method": 3
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_cookie": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient http_cookie": 2
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_user_agent": 4
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver http_host": 2
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient http_stat_code": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver dns_query": 4
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver tls.sni": 2
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient tls.cert_issuer": 2
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient tls.cert_subject": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient tls.cert_serial": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver ssh_protocol": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toserver file_data": 1
- [9308] 19/5/2019 -- 03:10:17 - (detect-engine-mpm.c:989) <Perf> (MpmStoreReportStats) -- AppLayer MPM "toclient file_data": 7
- [9308] 19/5/2019 -- 03:10:23 - (tmqh-flow.c:88) <Config> (TmqhFlowPrintAutofpHandler) -- AutoFP mode using "Hash" flow load balancer
- [9314] 19/5/2019 -- 03:10:23 - (log-pcap.c:762) <Info> (PcapLogInitRingBuffer) -- Initializing PCAP ring buffer for /data/nsm//log.%n.%t.pcap.
- [9314] 19/5/2019 -- 03:10:23 - (log-pcap.c:903) <Notice> (PcapLogInitRingBuffer) -- Ring buffer initialized with 0 files.
- [9315] 19/5/2019 -- 03:10:23 - (log-pcap.c:762) <Info> (PcapLogInitRingBuffer) -- Initializing PCAP ring buffer for /data/nsm//log.%n.%t.pcap.
- [9315] 19/5/2019 -- 03:10:23 - (log-pcap.c:903) <Notice> (PcapLogInitRingBuffer) -- Ring buffer initialized with 0 files.
- [9308] 19/5/2019 -- 03:10:23 - (flow-manager.c:815) <Config> (FlowManagerThreadSpawn) -- using 1 flow manager threads
- [9308] 19/5/2019 -- 03:10:23 - (flow-manager.c:976) <Config> (FlowRecyclerThreadSpawn) -- using 1 flow recycler threads
- [9308] 19/5/2019 -- 03:10:23 - (tm-threads.c:2157) <Notice> (TmThreadWaitOnThreadInit) -- all 3 packet processing threads, 4 management threads initialized, engine started.
- [9313] 19/5/2019 -- 03:10:23 - (source-pcap-file.c:176) <Info> (ReceivePcapFileLoop) -- Starting file run for ./exercises/pcaps/eod_exercise-1.pcap
- [9313] 19/5/2019 -- 03:10:23 - (util-checksum.c:89) <Info> (ChecksumAutoModeCheck) -- No packets with invalid checksum, assuming checksum offloading is NOT used
- [9313] 19/5/2019 -- 03:10:24 - (source-pcap-file-helper.c:149) <Info> (PcapFileDispatch) -- pcap file ./exercises/pcaps/eod_exercise-1.pcap end of file reached (pcap err code 0)
- [9308] 19/5/2019 -- 03:10:24 - (suricata.c:2843) <Notice> (SuricataMainLoop) -- Signal Received. Stopping engine.
- [9316] 19/5/2019 -- 03:10:24 - (flow-manager.c:794) <Perf> (FlowManager) -- 0 new flows, 0 established flows were timed out, 0 flows in closed state
- [9308] 19/5/2019 -- 03:10:25 - (suricata.c:1093) <Info> (SCPrintElapsedTime) -- time elapsed 1.744s
- [9317] 19/5/2019 -- 03:10:25 - (flow-manager.c:945) <Perf> (FlowRecycler) -- 163 flows processed
- [9313] 19/5/2019 -- 03:10:25 - (source-pcap-file.c:378) <Notice> (ReceivePcapFileThreadExitStats) -- Pcap-file module read 1 files, 15768 packets, 13594177 bytes
- [9308] 19/5/2019 -- 03:10:25 - (tmqh-flow.c:216) <Perf> (TmqhOutputFlowFreeCtx) -- AutoFP - Total flow handler queues - 2
- [9308] 19/5/2019 -- 03:10:25 - (counters.c:849) <Info> (StatsLogSummary) -- Alerts: 100
- [9308] 19/5/2019 -- 03:10:25 - (ippair.c:290) <Perf> (IPPairPrintStats) -- ippair memory usage: 414144 bytes, maximum: 16777216
- [9308] 19/5/2019 -- 03:10:25 - (host.c:294) <Perf> (HostPrintStats) -- host memory usage: 2254952 bytes, maximum: 33554432
- suricata: host.c:309: HostShutdown: Assertion `!((h->use_cnt_sc_atomic__) > 0)' failed.
- ./suri.sh: line 51: 9308 Aborted (core dumped) suricata -vvv -c /etc/suricata/suricata.yaml -k none -r $1 --runmode=autofp -s /home/training/sigdev.rules
- Signature Hits:
- The pcap - ./exercises/pcaps/eod_exercise-1.pcap has been processed
- Moloch -- https://localhost/moloch/sessions?expression=tags%20%3D%20eod_exercise-1.pcap
- Kibana SN-ALERTS -- https://localhost/app/kibana#/dashboard/SN-ALERTS
- Please note that it can take 10-40 sec for the events fully populate.
- training@SuricataThreatHunting:~$ ls -l
- total 216904
- drwxr-xr-x 2 training training 4096 Mar 12 22:21 Desktop
- drwxr-xr-x 2 training training 4096 Dec 27 16:10 Documents
- drwxr-xr-x 2 training training 4096 Mar 18 22:12 Downloads
- -rw-r--r-- 1 training training 35147 Jul 16 2018 LICENSE
- drwxr-xr-x 2 training training 4096 Dec 27 16:10 Public
- drwxr-xr-x 2 training training 4096 Dec 27 16:10 Videos
- -rw------- 1 root root 306511872 May 19 03:10 core
- -rw-r--r-- 1 root root 1899324 May 19 03:10 eve.json
- drwxr-xr-x 7 training training 4096 Mar 21 20:39 exercises
- -rwxr-xr-x 1 training training 705 Dec 27 20:59 reset_dashboards.sh
- -rw-r--r-- 1 training training 544 Feb 9 21:13 sigdev.rules
- drwxr-xr-x 2 training training 4096 Apr 10 22:15 slides
- -rw-r--r-- 1 root root 4139 May 19 03:10 stats.log
- -rwxr-xr-x 1 training training 2461 May 19 03:00 suri.sh
- drwxr-xr-x 2 root root 4096 May 17 08:38 vmexportprep
- training@SuricataThreatHunting:~$ ls -l /var/log/suricata/
- total 24
- drwxr-xr-x 2 logstash logstash 4096 Dec 16 21:15 StatsByDate
- drwxr-xr-x 2 logstash logstash 4096 Dec 13 16:36 certs
- drwxr-xr-x 2 logstash logstash 4096 Dec 13 16:36 core
- -rw-r--r-- 1 root root 1 May 19 03:09 eve.json
- drwxr-xr-x 2 logstash logstash 4096 Dec 13 16:36 files
- -rw-r--r-- 1 root root 3699 May 19 03:10 suricata.log
- training@SuricataThreatHunting:~$
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement