EMK 中moloch安装--抓取数据--碰到的错误

Dec  6 19:04:28 main.c:610 main(): THREAD 0x7fb975476800
Dec  6 19:04:28 main.c:169 parse_args(): WARNING: gethostname doesn't return a fully qualified name and getdomainname failed, this may cause issues when viewing pcaps - host-172-16-36-119
Dec  6 19:04:28 main.c:588 moloch_mlockall_init(): WARNING: memlock in limits.conf must be unlimited or at least 4000000, currently 64
Dec  6 19:04:28 http.c:216 moloch_http_send_sync(): 1/1 SYNC 200 http://172.16.36.120:9200/dstats/version/version/_source 0/15 1ms 2ms
Dec  6 19:04:28 http.c:216 moloch_http_send_sync(): 1/1 SYNC 200 http://172.16.36.120:9200/sequence/sequence/fn-host-172-16-36-119 0/100 0ms 7ms
Dec  6 19:04:28 http.c:216 moloch_http_send_sync(): 1/1 SYNC 200 http://172.16.36.120:9200/sequence/sequence/fn-host-172-16-36-119 2/170 0ms 30ms
Dec  6 19:04:28 http.c:216 moloch_http_send_sync(): 1/1 SYNC 200 http://172.16.36.120:9200/tags/tag/_search?size=3000 0/122 0ms 2ms
Dec  6 19:04:28 http.c:216 moloch_http_send_sync(): 1/1 SYNC 404 http://172.16.36.120:9200/stats/stat/host-172-16-36-119 0/77 0ms 1ms
Dec  6 19:04:28 http.c:216 moloch_http_send_sync(): 1/1 SYNC 200 http://172.16.36.120:9200/fields/field/_search?size=3000 0/59295 0ms 8ms
Dec  6 19:04:28 writer-simple.c:390 writer_simple_init(): INFO: Reseting pcapWriteSize to 262144 since it must be a multiple of 4096
Dec  6 19:04:28 writer-simple.c:280 writer_simple_thread(): THREAD 0x7fb965d72700
Dec  6 19:04:28 reader-libpcap.c:69 reader_libpcap_thread(): THREAD 0x7fb965371700
Dec  6 19:04:28 packet.c:933 moloch_packet_ip(): Initial Packet = 1512558268
Dec  6 19:04:28 packet.c:934 moloch_packet_ip(): 0 Initial Dropped = 0
Dec  6 19:04:28 reader-libpcap.c:54 reader_libpcap_pcap_cb(): ERROR - Moloch requires full packet captures caplen: 1530 pktlen: 4410
See https://github.com/aol/moloch/wiki/FAQ#Moloch_requires_full_packet_captures_error

Dec  6 19:04:28 main.c:610 main(): THREAD 0x7fe69e17c800

这个错误的现象是抓到的包为空,没有包数据的内容,因为抓包的时候,网卡都处理了文件内容,重新打包,拆分,所以抓取的内容看不到了,但是我们要的是原封不动的包数据。需要的处理是关闭网卡响应的功能

具体操作官网上面 有,两条命令输入关闭网卡响应的功能。

但是,有时候会存在不能关闭的现象,这是因为低版本的linux系统不支持,7.0(包括)以上的系统版本,支持关闭网卡的打包分拆功能。

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值