Is it not possible to run suricata offline mode as a daemon ?
I tried running this command but i get this error pcap offline mode can not run as daemon.
if so why is that i would like to have an instance running live and another one running offline
But if i have to use a socket i will have to install suricatasc on the computers of my team when i could just open a samba share and drop files in there, I think these are “Different use cases”.
Unless i understood this wrong
I feel like using a socket is much more work and harder then just using a simple share and dropping files in there