<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[suricata4: &#x27;logging directory ... doesn&#x27;t exist.&#x27; Actually, &#x27;&#x27;Permission denied&#x27;]]></title><description><![CDATA[<p dir="auto">Updated pfSense to 21.05-RELEASE and then needed to update suricata (to suricata4 - 4.1.9_5 - the only one avialable):</p>
<ul>
<li>Installed: suricata4 - 4.1.9_5 successfully</li>
<li>Doesn't appear in "Services"</li>
<li>Executing 'ls /usr/local/etc/suricata' lists the directory: suricata_51145_mvneta1</li>
<li>Executing: 'cd /usr/local/etc/suricata/suricata_51145_mvneta1', and this directory includes: suricata.yaml</li>
<li>Executing 'suricata -T -c ./suricata.yaml' gives:</li>
</ul>
<p dir="auto">&lt;quote&gt;<br />
4/6/2021 -- 08:42:53 - &lt;Info&gt; - Running suricata under test mode<br />
Error opening file /var/log/suricata/suricata_mvneta151145/suricata.log<br />
4/6/2021 -- 08:42:53 - &lt;Notice&gt; -- This is Suricata version 4.1.9 RELEASE<br />
4/6/2021 -- 08:42:53 - &lt;Info&gt; -- CPUs/cores online: 2<br />
4/6/2021 -- 08:42:53 - &lt;Info&gt; -- HTTP memcap: 67108864<br />
4/6/2021 -- 08:42:53 - &lt;Error&gt; -- [ERRCODE: SC_ERR_LOGDIR_CONFIG(116)] - The logging directory "/var/log/suricata/suricata_mvneta151145" supplied by ./suricata.yaml (default-log-dir) doesn't exist. Shutting down the engine<br />
&lt;/quote&gt;</p>
<ul>
<li>Access to /var/log/suricata/suricata_mvneta151145 returns 'Permission denied.'</li>
<li>Access to /var/log/suricata/ gives 'Permission denied.' (It's actually 'root : wheel')</li>
</ul>
<p dir="auto">Any suggestions for a fix? Netgate SG-3100. Tried repeated uninstall / install.</p>
]]></description><link>https://forum.netgate.com/topic/164194/suricata4-logging-directory-doesn-t-exist-actually-permission-denied</link><generator>RSS for Node</generator><lastBuildDate>Fri, 12 Jun 2026 21:17:07 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/164194.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 04 Jun 2021 14:47:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to suricata4: &#x27;logging directory ... doesn&#x27;t exist.&#x27; Actually, &#x27;&#x27;Permission denied&#x27; on Mon, 07 Jun 2021 18:31:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bmeeks">@<bdi>bmeeks</bdi></a> Stunning painless fix. Greatly appreciated.</p>
]]></description><link>https://forum.netgate.com/post/986663</link><guid isPermaLink="true">https://forum.netgate.com/post/986663</guid><dc:creator><![CDATA[bdgreen]]></dc:creator><pubDate>Mon, 07 Jun 2021 18:31:26 GMT</pubDate></item><item><title><![CDATA[Reply to suricata4: &#x27;logging directory ... doesn&#x27;t exist.&#x27; Actually, &#x27;&#x27;Permission denied&#x27; on Fri, 04 Jun 2021 17:57:09 GMT]]></title><description><![CDATA[<p dir="auto">Suricata is crashing PHP itself during the installation process, that's why it does not show up under SERVICES (it never completes installation). And because it does not successfully complete installation, it  never gets to the part where it creates that logging directory.</p>
<p dir="auto">You can try applying the PHP patch discussed in this post:  <a href="https://forum.netgate.com/topic/161050/snort-won-t-start-after-upgrade-to-21-02-on-sg-3100/24?_=1622736263256">https://forum.netgate.com/topic/161050/snort-won-t-start-after-upgrade-to-21-02-on-sg-3100/24?_=1622736263256</a>. Apply that patch as described, being sure to follow the steps to either restart <code>php</code> or reboot the firewall, before attempting the Suricata install again. Even though the patch is posted in a Snort thread, the problem with PHP is common to both Snort and Suricata on SG-3100 appliances.</p>
]]></description><link>https://forum.netgate.com/post/986230</link><guid isPermaLink="true">https://forum.netgate.com/post/986230</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Fri, 04 Jun 2021 17:57:09 GMT</pubDate></item></channel></rss>