# Suricata is not working as expected in Windows server

**URL:** https://forum.suricata.io/t/suricata-is-not-working-as-expected-in-windows-server/2728
**Category:** Help
**Tags:** windows
**Created:** [August 30, 2022, 3:21pm UTC](https://forum.suricata.io/t/suricata-is-not-working-as-expected-in-windows-server/2728 "2022-08-30T15:21:35Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![mkaruppiah](https://avatars.discourse-cdn.com/v4/letter/m/85f322/32.png) [@mkaruppiah](https://forum.suricata.io/u/mkaruppiah)
#### Post date: [August 30, 2022, 3:21pm UTC](https://forum.suricata.io/t/suricata-is-not-working-as-expected-in-windows-server/2728/1 "2022-08-30T15:21:35Z")

</div>

Hi,

We have downloaded and installed latest package from the portal. But is not working. Please refer to the below error and advise further action.

C:\Program Files\Suricata\>suricata.exe -c suricata.yaml -s signatures.rules -i eth0

29/8/2022 – 17:50:26 - - Running as service: no

29/8/2022 – 17:50:26 - - Configuration node ‘HOME\_NET’ redefined.

29/8/2022 – 17:50:26 - - Configuration node ‘HOME\_NET’ redefined.

29/8/2022 – 17:50:26 - - Configuration node ‘HOME\_NET’ redefined.

29/8/2022 – 17:50:26 - - Configuration node ‘HOME\_NET’ redefined.

29/8/2022 – 17:50:26 - - Configuration node ‘EXTERNAL\_NET’ redefined.

Error opening file /var/log/suricata//suricata.log

29/8/2022 – 17:50:27 - - This is Suricata version 6.0.6 RELEASE running in SYSTEM mode

29/8/2022 – 17:50:27 - - [ERRCODE: SC\_ERR\_CONF\_YAML\_ERROR(242)] - App-Layer protocol sip enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.

29/8/2022 – 17:50:27 - - [ERRCODE: SC\_ERR\_CONF\_YAML\_ERROR(242)] - App-Layer protocol mqtt enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.

29/8/2022 – 17:50:27 - - [ERRCODE: SC\_ERR\_CONF\_YAML\_ERROR(242)] - App-Layer protocol rdp enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.

C:\Program Files\Suricata\>

---

<div class="post-metadata">

### Author: ![Sheru](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/sheru/32/1491_2.png) [@Sheru](https://forum.suricata.io/u/Sheru)
#### Post date: [August 31, 2022, 1:44pm UTC](https://forum.suricata.io/t/suricata-is-not-working-as-expected-in-windows-server/2728/2 "2022-08-31T13:44:05Z")

</div>

In the suricata.yaml file you should change the path to the log file.

As seen in your trace:

> Error opening file /var/log/suricata//suricata.log

Is not a valid path for a windows system.
