• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Suricata not limiting log sizes by default

Scheduled Pinned Locked Moved IDS/IPS
4 Posts 2 Posters 1.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    stephenw10 Netgate Administrator
    last edited by May 16, 2018, 5:23 PM

    Although the default setting in Suricata is to have log management enabled and per log size limits defined that does not appear to be applied at install.

    Those tags do not appear in the config file unless the Log Management tab is saved in the GUI.

    As a result the Suricata logs can quickly fill /var if it's a RAM drive.

    I tested this on a fresh 2.4.3 install today but it would be good to see it confirmed.

    Steve

    1 Reply Last reply Reply Quote 1
    • S
      SteveITS Galactic Empire
      last edited by SteveITS Jun 6, 2018, 7:40 PM Jun 6, 2018, 7:15 PM

      Ugh, yes, we found this out the hard way today when a client's SG-3100's 7 GB drive filled up (showed 109% full...). Fortunately I could SSH in and delete the 6.5 GB log file, but still had to restore the configuration.

      Can we please have log rotation enabled by default?

      Edit: I just got what you said...you're saying it is on by default when the Suricata package is installed, but if you don't save the Logs Management tab it will revert to not rotating the logs, on the first boot?

      Edit: re: confirmation, found this on two other client routers as well.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire
        last edited by Jun 7, 2018, 4:18 PM

        Can you, or someone, create a bug in https://redmine.pfsense.org/projects/pfsense-packages? Apparently I cannot create new bugs there, though I did once in the past.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Jun 11, 2018, 3:17 PM

          Yes, though usually attracting the attention of @bmeeks is the best way to get traction on this. 😉

          Steve

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received