Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disk full with packet logs

    Scheduled Pinned Locked Moved IDS/IPS
    4 Posts 3 Posters 404 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bhjitsense
      last edited by

      I enabled packet logging in Suricata several days ago. Now my disk is full and I’m pretty sure this is causing it. I wasn’t sure how to view the logs in the first place through the GUI, and I can’t access the GUI now. Where are these logs so I can delete them via shell?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        /var/log/suricata/

        1 Reply Last reply Reply Quote 0
        • B
          bhjitsense
          last edited by

          Thanks. That took care of it.
          In the GUI, is there not an easy way to view/export the .pcap files that have been logged?

          bmeeksB 1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks @bhjitsense
            last edited by

            @bhjitsense said in Disk full with packet logs:

            Thanks. That took care of it.
            In the GUI, is there not an easy way to view/export the .pcap files that have been logged?

            No. You can see the files using DIAGNOSTICS > EDIT FILE from the pfSense menu, but there is nothing within the Suricata GUI for looking at the .pcap files. It is the admin's responsibility to either view them using some CLI tool or export them off the box over to another server for analysis with third-party tools. The PHP system of the firewall does not provide a great programming environment for opening up and viewing large files.

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.