On Fri, Jun 21, 2019 at 5:30 PM fadi abusafat <
fabusa...@gmail.com> wrote:
>
> Hi everyone.
>
> I would like to analyze pcap file through Suricata into Selks but it not works. every time I run it, it provides me with errors that mentioned ( The custom type "workers" does not exist for this runmode type " PC AP_FILE". Please use --list-runmodes to see available sutome types for this runmode.
>
> I run the following command to analyse pcap file :
>
> suricata -c /etc/suricata/suricata.yaml -r Desktop/ Pcap\ file / wrcc.pcap
>
You should probably try
suricata -c /etc/suricata/suricata.yaml -r Desktop/ Pcap\ file /
wrcc.pcap --runmode=autofp
Than be careful as to the timespan of the dashboards you are using to
look at the pcap - as th epcap timestamp may be diff than from
today/now :)
> This is an image of my works.
>
> Anyone could help me please how to analyse Pcap file through Suricata Selks.
>
> Thank you so much.
>
> Many Thanks.
>
> Fadi !!!!
>
> --
> IRC: Let's talk about SELKS on Freenode IRC on the #SELKS channel
> Wiki:
https://github.com/StamusNetworks/SELKS/wiki
> GitHub:
https://github.com/StamusNetworks/SELKS
> Blog:
https://www.stamus-networks.com/theblog/
> Twitter: @StamusN
> g+: Stamus Networks
> ---
> You received this message because you are subscribed to the Google Groups "SELKS" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to
selks+un...@googlegroups.com.
> To post to this group, send email to
se...@googlegroups.com.
> To view this discussion on the web visit
https://groups.google.com/d/msgid/selks/45614601-1cd0-4d94-a224-38639418ee34%40googlegroups.com.
> For more options, visit
https://groups.google.com/d/optout.
--
Regards,
Peter Manev