We are currently facing some problems with Suricata and mainly around the sending of logs. At any moment, Suricata stops to send logs to our log collector. The service status is still ‘Running’ and there is no error messages.
We are sending these logs in syslog :
- eve-log: enabled: yes filetype: syslog level: Warning
We saw that all of these logs are also displayed in the systemD journal. When we are typing “systemctl status suricata” or “journalctl -fu suricata” all logs are displayed.
We have already faced this kind of situation with another program which spammed this entry and it revealed it was the root cause of a problem we get.
So, is there a possibility to continue to send these logs by Syslog and avoid to have these logs in SystemD Journal ?
Suricata : 6.0.3 OS : Ubuntu 18.04.6 RAM : 4 GO
Thanks in advance for your reply,