Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@latitude:/home/user/malware/909052404576dd98c968ebfcf73a99f6/tmp# strace /opt/suricata-git.latest/src/suricata -c ./suricata.yaml -S /home/user/rules/suricata4.local.rules -r ./merged.pcap -k none -vvv 2>&1 | grep .log
- read(3, " \toff\nnoglob \toff\nnolog"..., 128) = 128
- openat(AT_FDCWD, "./suricata.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 3
- openat(AT_FDCWD, "./fast.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 141[18802] 30/7/2019 -- 11:46:08 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- fast output device (regular) initialized: fast.log
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 144[18802] 30/7/2019 -- 11:46:08 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- eve-log output device (regular) initialized: eve.json
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'alert'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'http'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dns'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tls'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'files'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smtp'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ftp'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'nfs'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smb'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tftp'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ikev2'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'krb5'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'snmp'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dhcp'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 122[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ssh'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 124[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'stats'
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 123[18802] 30/7/2019 -- 11:46:08 - (runmodes.c:625) <Config> (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'flow'
- openat(AT_FDCWD, "./stats.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 6
- write(1, "[18802] 30/7/2019 -- 11:46:08 - "..., 143[18802] 30/7/2019 -- 11:46:08 - (util-logopenfile.c:476) <Info> (SCConfLogOpenGeneric) -- stats output device (regular) initialized: stats.log
- openat(AT_FDCWD, "./packet_stats.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
- openat(AT_FDCWD, "./rule_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
- openat(AT_FDCWD, "./keyword_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
- openat(AT_FDCWD, "./rule_group_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
- openat(AT_FDCWD, "./prefilter_perf.log", O_WRONLY|O_CREAT|O_APPEND, 0666) = 4
- root@latitude:/home/user/malware/909052404576dd98c968ebfcf73a99f6/tmp# grep default-log-dir: ./suricata.yaml
- default-log-dir: /tmp/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement