# Suricata not running

**URL:** <https://forum.suricata.io/t/suricata-not-running/3877>\
**Category:** Help\
**Tags:** suricata\
**Created:** [August 30, 2023, 6:30pm UTC](https://forum.suricata.io/t/suricata-not-running/3877 "2023-08-30T18:30:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hunt](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/hunt/32/2326_2.png) [@hunt](https://forum.suricata.io/u/hunt)\
**Post date:** [August 30, 2023, 6:30pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/1 "2023-08-30T18:30:50Z")

</div>

Hello Ninjas,

I need assistance with my Suricata conf file.  
Service isn’t running.  
Kindly find attached.

Regards,  
Hunt

 ![Screenshot 2023-08-30 182741](https://canada1.discourse-cdn.com/flex030/uploads/suricata/original/2X/a/a7186cf03982b44791301bb38c89a14bded8b300.png)  
 ![Screenshot 2023-08-30 182901](https://canada1.discourse-cdn.com/flex030/uploads/suricata/original/2X/d/d02884d464e366fb78f4536bc4e5da86ff72fd25.png)

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [August 30, 2023, 6:59pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/2 "2023-08-30T18:59:49Z")

</div>

Hi,

what version of Suricata are you running, how does your suricata.yaml look like?  
Also post the suricata.log which might contain the relevant part that is failing.

---

<div class="post-metadata">

**Author:** ![hunt](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/hunt/32/2326_2.png) [@hunt](https://forum.suricata.io/u/hunt)\
**Post date:** [August 31, 2023, 5:54pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/3 "2023-08-31T17:54:03Z")

</div>

Hi Herz,

Kindly find below the information requested.

Suricata version 7.0.0.

 ![Screenshot 2023-08-31 175217](https://canada1.discourse-cdn.com/flex030/uploads/suricata/original/2X/1/1df9db35e4f446fac3cc8d117d49034fd78156b1.png)

[suricata.yaml](https://forum.suricata.io/uploads/short-url/ciHiIaDhS9t2RXsyNHLNFQc81Rc.yaml) (83.0 KB)

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [August 31, 2023, 6:43pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/4 "2023-08-31T18:43:12Z")

</div>

The log doesn’t seem that useful. I wonder if `journalctl -xf -u suricata` has anymore detail?

Also, how did you install Suricata? And your OS? What was the source of the package if any used.

Thanks,

---

<div class="post-metadata">

**Author:** ![hunt](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/hunt/32/2326_2.png) [@hunt](https://forum.suricata.io/u/hunt)\
**Post date:** [September 1, 2023, 10:45am UTC](https://forum.suricata.io/t/suricata-not-running/3877/5 "2023-09-01T10:45:02Z")

</div>

> **[Network IDS integration - Proof of Concept guide · Wazuh documentation](https://documentation.wazuh.com/current/proof-of-concept-guide/integrate-network-ids-suricata.html)**
>
> User manual, installation and configuration guides. Learn how to get the most out of the Wazuh platform.

 ![Screenshot 2023-09-01 104207](https://canada1.discourse-cdn.com/flex030/uploads/suricata/original/2X/b/baf1f7db787f2871d396125b5d91a9c57ef94cb9.png)

Linux hackwell 6.4.0-kali3-amd64 #1 SMP PREEMPT\_DYNAMIC Debian 6.4.11-1kali1 (2023-08-21) x86\_64 GNU/Linux

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [September 1, 2023, 2:31pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/6 "2023-09-01T14:31:28Z")

</div>

Ah, sorry… I see that Suricata is started with `-D` so the journal won’t have much. This is unfortunately with the Debian packages.

Try running in the foreground on command line.

- Make sure the service is stopped: `systemctl stop suricata`
- Then run: `/usr/bin/suricata --af-packet -c /etc/suricata/suricata.yaml --pidfile /run/suricata.pid`

This is the same command line from the systemd unit file minus the daemonization option, so should show more output.

---

<div class="post-metadata">

**Author:** ![hunt](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/hunt/32/2326_2.png) [@hunt](https://forum.suricata.io/u/hunt)\
**Post date:** [September 1, 2023, 4:10pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/7 "2023-09-01T16:10:48Z")

</div>

![Screenshot 2023-09-01 104207](https://canada1.discourse-cdn.com/flex030/uploads/suricata/original/2X/d/d17c17d488520c6f59754434be0494763e95dacf.png)

this is the result … another error

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [September 1, 2023, 4:21pm UTC](https://forum.suricata.io/t/suricata-not-running/3877/8 "2023-09-01T16:21:09Z")

</div>

Remove the pid file as the error says, then restart using systemctl. I’m not actually sure where this systemd file is coming from, but it doesn’t appear to handle the PID file properly.
