I was just trying to get a fix on how many packets were being dropped by Suricata on an up to date SO standalone system when I could not find the stats.log file even though it is configured to be populated by suricata.yaml. Upon closer inspection, after restarting Suricata the stats file would appear, but a while later it would disappear. I then looked more broadly across all Suricata instances of a couple of other modern SO systems and stats.log was missing in all cases. Even my older pre-Elastic SO systems exhibit this behavior.
However, when I check with lsof on all of these systems I see every one of the missing stats.log files are accounted for but marked "(deleted)". I do not know what might be deleting them.
Is anyone else seeing this on their SO sensors? Specifically, for those using Suricata under SO, on your SO sensor(s) do you get zero results from this command