We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ログ集約処理の実行直後に、新たなログファイルが生成(ローテート)され、その後rmコマンドが実行された場合にログの欠損が生じる可能性がある。
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/bro.sh
Lines 17 to 18 in 6604b9b
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/p0f.sh
Lines 4 to 6 in 6604b9b
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/suricata.sh
Lines 5 to 6 in 6604b9b
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/yaf.sh
Lines 3 to 19 in 6604b9b
集約対象のログファイルのリストを変数に格納した後、集約処理や削除処理を実行する際に当該変数を参照する。
The text was updated successfully, but these errors were encountered:
Merge remote-tracking branch 'origin/main' into bug-#175
5d34105
Merge pull request #183 from nttcom/bug-#175
f5c86e4
#175 ごく稀にログが欠損する可能性を排除できない問題を修正
tkhr-ueda
Successfully merging a pull request may close this issue.
問題点
ログ集約処理の実行直後に、新たなログファイルが生成(ローテート)され、その後rmコマンドが実行された場合にログの欠損が生じる可能性がある。
該当する処理
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/bro.sh
Lines 17 to 18 in 6604b9b
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/p0f.sh
Lines 4 to 6 in 6604b9b
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/suricata.sh
Lines 5 to 6 in 6604b9b
OsecT/osect_sensor/Infrastructure/edge_cron/work/ot_tools/yaf.sh
Lines 3 to 19 in 6604b9b
解決方針
集約対象のログファイルのリストを変数に格納した後、集約処理や削除処理を実行する際に当該変数を参照する。
The text was updated successfully, but these errors were encountered: