New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Error while running #2
Comments
Hi, did you add kafka section to your suricata.yaml? seen plugin can't find some necessary parameters. |
Hi @Center-Sun , added this at end of file , exact copy paste in suricata.yaml
I replaced kafka:port with my own server details. plugin is detected by suricata but it can't read parameters . Request you to try a demo of it in a Virtual Box maybe some things changed with 6.0.4 |
Hi @cybersecurity99 , It's worked in my suricata-6.0.4.
Hope it can helps you |
Hi @Center-Sun sorry for late reply
I get this in suricata.log but my kafka is empty Can you tell what may be the reason ? or any file I need to check to find issue. This kafka issue tougher than finding One Piece :) |
Hi @cybersecurity99 ,i don't have any idea now, because according to the logs, it was working fine. Did you find any exceptions or errors? |
@Center-Sun I tried to look for any errors but I don't find any . Also I am unable to locate where my logs going because it is not writing to eve.json on disk or to kafka . It just created topic suricata . |
Also what's this client_id ? |
it's a property of kafka client |
This issue may be related to kafka broker🤔 |
I am facing the same issue with suricata suricata-6.0.4. @cybersecurity99 have you found a fix?
|
@ImadYamane Worked for me |
@Center-Sun Hi I wanted to know how we configure bucket size in this , I am not sure about the data rate it will transmit . can you help in this regard |
@cybersecurity99 Hi , can't configure now ,but this plugin based on librdkafka ,it's support many configuration property https://github.com/edenhill/librdkafka/blob/master/STATISTICS.md . you can modify this plugin to support bucket size or others |
HI @Center-Sun isn't files in src folder are hard coded |
Hi @cybersecurity99 , No other options are hard-coded , I only used these four options. |
11/4/2022 -- 12:44:36 - - brokers parameter required!
thread '' panicked at 'explicit panic', src/lib.rs:55:13
note: run with
RUST_BACKTRACE=1
environment variable to display a backtracefatal runtime error: failed to initiate panic, error 5
Aborted (core dumped)
The text was updated successfully, but these errors were encountered: