Advertisement
travisbgreen

Untitled

Jul 30th, 2019
240
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.47 KB | None | 0 0
  1. root@latitude:/home/user/malware/909052404576dd98c968ebfcf73a99f6/tmp# strace /opt/suricata-git.latest/src/suricata -c ./suricata.yaml -S /home/user/rules/suricata4.local.rules -r ./merged.pcap -k none -vvv 2>&1 | grep .log
  2. read(3, " \toff\nnoglob \toff\nnolog"..., 128) = 128
  3. openat(AT_FDCWD, "./suricata.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 3
  4. openat(AT_FDCWD, "./fast.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
  5. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 141[18802] 30/7/2019 -- 11:46:08 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- fast output device (regular) initialized: fast.log
  6. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 144[18802] 30/7/2019 -- 11:46:08 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- eve-log output device (regular) initialized: eve.json
  7. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'alert'
  8. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'http'
  9. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dns'
  10. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tls'
  11. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'files'
  12. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smtp'
  13. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ftp'
  14. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'nfs'
  15. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smb'
  16. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tftp'
  17. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ikev2'
  18. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'krb5'
  19. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'snmp'
  20. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dhcp'
  21. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ssh'
  22. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'stats'
  23. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'flow'
  24. openat(AT_FDCWD, "./stats.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 6
  25. write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 143[18802] 30/7/2019 -- 11:46:08 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- stats output device (regular) initialized: stats.log
  26. openat(AT_FDCWD, "./packet_stats.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
  27. openat(AT_FDCWD, "./rule_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
  28. openat(AT_FDCWD, "./keyword_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
  29. openat(AT_FDCWD, "./rule_group_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
  30. openat(AT_FDCWD, "./prefilter_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
  31. root@latitude:/home/user/malware/909052404576dd98c968ebfcf73a99f6/tmp# grep default-log-dir: ./suricata.yaml
  32. default-log-dir: /tmp/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement