• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Suricata Packet Log Location

Scheduled Pinned Locked Moved pfSense Packages
3 Posts 2 Posters 987 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    Trel
    last edited by Jul 9, 2014, 2:48 PM

    I turned on packet logging for an interface to test with, but I can't find where to actually access those logs.

    I kept getting the "Suspicious User Agent" alert so I wanted to look at the packets to see what actually it's flagging.

    1 Reply Last reply Reply Quote 0
    • C
      Cino
      last edited by Jul 9, 2014, 3:11 PM

      @Trel:

      I turned on packet logging for an interface to test with, but I can't find where to actually access those logs.

      I kept getting the "Suspicious User Agent" alert so I wanted to look at the packets to see what actually it's flagging.

      i get a ton of them, mostly false positives for me but look here /var/log/suricata/suricata_'interface id'

      1 Reply Last reply Reply Quote 0
      • T
        Trel
        last edited by Jul 9, 2014, 3:20 PM Jul 9, 2014, 3:15 PM

        @Cino:

        @Trel:

        I turned on packet logging for an interface to test with, but I can't find where to actually access those logs.

        I kept getting the "Suspicious User Agent" alert so I wanted to look at the packets to see what actually it's flagging.

        i get a ton of them, mostly false positives for me but look here /var/log/suricata/suricata_'interface id'

        Based on the port being used and the  machine it's coming from, I'm fairly certain I know what's triggering it

        and if I'm reading the rule right: http://doc.emergingthreats.net/bin/view/Main/2001891

        That's being triggered by "3a" or " agent" being in the user agent?

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received