Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disk 109% full

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 4 Posters 712 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bhjitsense
      last edited by

      I enabled Suricata packet logging a while back. Wasn't thinking. I don't know where these logs are stored in either the fall structure, or in the GUI. Where do I go to delete these?

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        Hi,

        Have a look at the part of the forum where packages (Suricata) is discussed.
        You'll find what your are looking for.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          They are in /var/log/suricata. Stop Suricata, delete those logs.
          Go into the Suricata log management settings enable auto log management, set a directory size limit of something reasonable then re-save those settings.
          Monitor it for a few days to be sure it's rotating the logs as expected.

          Steve

          1 Reply Last reply Reply Quote 1
          • bmeeksB
            bmeeks
            last edited by

            @stephenw10 is spot on. On the LOG MGMT tab are settings for controlling the size of each active log and for retention of rotated logs.

            There is also a setting for controlling the maximum allowed size of the entire /var/log/suricata tree. Be sure to allow for some overrun when setting the size limit, though. This is because the log managment feature is handled by a cron task that runs periodically to check on and clean up logs. On a busy network, there can be a lot of log growth that happens in between the 5-minute checks the cron task performs.

            Unless you have a quite large hard disk (say at least 30 GB or more), then enabling packet logging can be dicey on a busy network. You will need to limit the log size and particularly the retention (the number of old, rotated logs/files kept on disk).

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.