Hello community!
I have built from source suricata and NTOP/pf_ring and run suricata using the following switches:
Looking in stats.log for a pf_ring related line and I don’t see anything.
You can use suricatasc to query the run and capture mode of suricata: suricatasc -c capture-mode /var/run/suricata/suricata-command.socket (note that the socket name is taken from suricata.yaml (if present). Otherwise, a default value is used.
suricatasc
suricatasc -c capture-mode /var/run/suricata/suricata-command.socket
suricata.yaml
Perfect, that is it! Thank you!