# How to start and stop Suricata-IDS from CLI?

**URL:** <https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187>\
**Category:** Help\
**Created:** [November 15, 2023, 6:39am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187 "2023-11-15T06:39:17Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [November 15, 2023, 6:39am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/1 "2023-11-15T06:39:17Z")

</div>

Hello,  
I ran Suricata-IDS with the following command:

```auto
# suricata -c /etc/suricata/suricata.yaml --af-packet -D
```

I have two questions:

1- How can I stop it?

2- I used `ps -A` command and found Suricata-IDS process, then:

```auto
# kill -9 ppid
```

Then, I checked the process list again and no more Suricata-IDS. I wanted to re-run Suricata-IDS, but:

```auto
# suricata -c /etc/suricata/suricata.yaml --af-packet -D
i: suricata: This is Suricata version 7.0.2 RELEASE running in SYSTEM mode
E: pidfile: pid file '/var/run/suricata.pid' exists but appears stale. Make sure Suricata is not running and then remove /var/run/suricata.pid. Aborting!
```

How to solve it?

Thank you.

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [November 15, 2023, 8:33am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/2 "2023-11-15T08:33:51Z")

</div>

Why are you using signal 9 (SIGKILL)?

---

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [November 15, 2023, 11:39am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/3 "2023-11-15T11:39:53Z")

</div>

Hello,  
Thank you so much for your reply.  
I just wanted to terminate it **immediately**. Is this the problem?  
How can I stop it? I installed the Suricata-IDS from source code and no service has been created. So, I can’t use **systemctl** command to control Sucricata-IDS.

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [November 15, 2023, 2:17pm UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/4 "2023-11-15T14:17:40Z")

</div>

I suggest you read a bit more on signals, because KILL should only be used if other signals do not end the process.

---

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [November 16, 2023, 7:31pm UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/5 "2023-11-16T19:31:04Z")

</div>

Hello,  
Thanks again.  
No idea why a service wasn’t created? How can I stop Suricata-IDS?

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [November 16, 2023, 7:41pm UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/6 "2023-11-16T19:41:14Z")

</div>

> [@Hack3rcon](#):
>
> No idea why a service wasn’t created? How can I stop Suricata-IDS?

Creating the service details was usually a distribution packaging job as distributions can differ enough that we couldn’t do it for all. We do provide a sample unit file you can install though:

```shell
cp etc/suricata.service /etc/systemd/system

```

Running from source does often mean dealing with some of the packaging level details yourself.

---

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [November 22, 2023, 7:18am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/7 "2023-11-22T07:18:15Z")

</div>

Hello,  
Thank you so much for your reply.  
I copied the `suricata.service` file from the installation directory to `/etc/systemd/system` directory, then I tried to run Suricata-IDS:

```auto
# systemctl status suricata
× suricata.service - Suricata Intrusion Detection Service
     Loaded: loaded (/etc/systemd/system/suricata.service; disabled; preset: enabled)
     Active: failed (Result: exit-code) since Wed 2023-11-22 02:11:31 EST; 3s ago
   Duration: 4ms
    Process: 1418 ExecStartPre=/bin/rm -f /var/run/suricata.pid (code=exited, status=0/SUCCESS)
    Process: 1419 ExecStart=/sbin/suricata -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid $OPTIONS (code=exited, status=1/FAILURE)
   Main PID: 1419 (code=exited, status=1/FAILURE)
        CPU: 5ms

Nov 22 02:11:31 Suricata suricata[1419]: --group <group> : run suricata as this group after init
Nov 22 02:11:31 Suricata suricata[1419]: --erf-in <path> : process an ERF file
Nov 22 02:11:31 Suricata suricata[1419]: --unix-socket[=<file>] : use unix socket to control suricata work
Nov 22 02:11:31 Suricata suricata[1419]: --reject-dev <dev> : send reject packets from this interface
Nov 22 02:11:31 Suricata suricata[1419]: --include <path> : additional configuration file
Nov 22 02:11:31 Suricata suricata[1419]: --set name=value : set a configuration value
Nov 22 02:11:31 Suricata suricata[1419]: To run the engine with default configuration on interface eth0 with signature file "signatures.rules", run the command as:
Nov 22 02:11:31 Suricata suricata[1419]: /sbin/suricata -c suricata.yaml -s signatures.rules -i eth0
Nov 22 02:11:31 Suricata systemd[1]: suricata.service: Main process exited, code=exited, status=1/FAILURE
Nov 22 02:11:31 Suricata systemd[1]: suricata.service: Failed with result 'exit-code'.
```

Where is the problem?

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [November 22, 2023, 9:00am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/8 "2023-11-22T09:00:34Z")

</div>

I would suggest trying the actual commandline from the service file manually first.

---

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [November 22, 2023, 9:26am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/9 "2023-11-22T09:26:13Z")

</div>

Hello,  
Thank you so much for your reply.  
If you mean the command `/sbin/suricata -c suricata.yaml -s signatures.rules -i NIC` then:

```auto
# /sbin/suricata -c /etc/suricata/suricata.yaml -s signatures.rules -i Control
i: suricata: This is Suricata version 7.0.2 RELEASE running in SYSTEM mode
E: af-packet: Problem with config file
W: detect: No rule files match the pattern signatures.rules
i: threads: Threads created -> W: 8 FM: 1 FR: 1 Engine started.
```

As you see, it shows me **E: af-packet: Problem with config file** error. My `af-packet` section is:

```auto
af-packet:
  - interface: Client
    threads: 1
    defrag: no
    cluster-type: cluster_flow
    cluster-id: 98
    copy-mode: ips
    copy-iface: Server
    buffer-size: 64535
    use-mmap: yes
  - interface: Server
    threads: 1
    cluster-id: 97
    defrag: no
    cluster-type: cluster_flow
    copy-mode: ips
    copy-iface: Client
    buffer-size: 64535
    use-mmap: yes
```

What is wrong?

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [November 22, 2023, 9:29am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/10 "2023-11-22T09:29:31Z")

</div>

Interface `Control` is not in your af-packet config, nor is the `default` interface, so af-packet doesn’t know which settings to apply to it. The error is not very clear.

---

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [November 22, 2023, 9:40am UTC](https://forum.suricata.io/t/how-to-start-and-stop-suricata-ids-from-cli/4187/11 "2023-11-22T09:40:12Z")

</div>

Thanks again.  
Can you tell me how can I add it? Should I add the parameters like `threads`, `cluster-id` and etc. for it?  
I added a section like the below at the end of the `af-packet` section:

```auto
- interface: Control
    cluster-id: 96
    cluster-type: cluster_flow
    defrag: yes
    use-mmap: yes
    tpacket-v3: yes
```

Then:

```auto
# /sbin/suricata -c /etc/suricata/suricata.yaml -s signatures.rules -i Control
i: suricata: This is Suricata version 7.0.2 RELEASE running in SYSTEM mode
W: detect: No rule files match the pattern signatures.rules
i: threads: Threads created -> W: 8 FM: 1 FR: 1 Engine started.
```

The first error solved, but how about:

```auto
W: detect: No rule files match the pattern signatures.rules
```

I tried `systemctl start suricata`, but got the same error!
