33 #if defined(HAVE_DIRENT_H) && defined(HAVE_FNMATCH_H)
34 #define INIT_RING_BUFFER
58 #define DEFAULT_LOG_FILENAME "pcaplog"
59 #define MODULE_NAME "PcapLog"
60 #define MIN_LIMIT 4 * 1024 * 1024
61 #define DEFAULT_LIMIT 100 * 1024 * 1024
62 #define DEFAULT_FILE_LIMIT 0
64 #define LOGMODE_NORMAL 0
65 #define LOGMODE_MULTI 1
73 #define RING_BUFFER_MODE_DISABLED 0
74 #define RING_BUFFER_MODE_ENABLED 1
76 #define TS_FORMAT_SEC 0
77 #define TS_FORMAT_USEC 1
79 #define USE_STREAM_DEPTH_DISABLED 0
80 #define USE_STREAM_DEPTH_ENABLED 1
82 #define HONOR_PASS_RULES_DISABLED 0
83 #define HONOR_PASS_RULES_ENABLED 1
85 #define PCAP_SNAPLEN 262144
86 #define PCAP_BUFFER_TIMEOUT 1000000 // microseconds
87 #define PCAP_PKTHDR_SIZE 16
90 #ifndef PCAP_NETMASK_UNKNOWN
91 #define PCAP_NETMASK_UNKNOWN 0xffffffff
118 #define MAX_FILENAMELEN 513
130 LZ4F_compressionContext_t lz4f_context;
131 LZ4F_preferences_t lz4f_prefs;
132 FILE *pcap_buf_wrapper;
151 struct pcap_pkthdr *
h;
177 uint32_t thread_number;
179 int timestamp_format;
186 int filename_part_cnt;
187 struct timeval last_pcap_dump;
203 static const char timestamp_pattern[] =
".*?(\\d+)(\\.(\\d+))?";
204 static pcre2_code *pcre_timestamp_code = NULL;
205 static pcre2_match_data *pcre_timestamp_match = NULL;
215 static void PcapLogFileDeInitCtx(
OutputCtx *);
224 .ConditionFunc = PcapLogCondition,
225 .ThreadInitFunc = PcapLogDataInit,
226 .ThreadDeinitFunc = PcapLogDataDeinit,
227 .ThreadExitPrintStatsFunc = NULL,
236 #define PCAPLOG_PROFILE_START \
237 uint64_t pcaplog_profile_ticks = UtilCpuGetTicks()
239 #define PCAPLOG_PROFILE_END(prof) \
240 (prof).total += (UtilCpuGetTicks() - pcaplog_profile_ticks); \
261 return !PacketIsTunnelChild(
p);
280 comp->pcap_buf_wrapper = NULL;
297 uint64_t bytes_written = LZ4F_compressEnd(comp->lz4f_context,
299 if (LZ4F_isError(bytes_written)) {
300 SCLogError(
"LZ4F_compressEnd: %s", LZ4F_getErrorName(bytes_written));
303 if (fwrite(comp->
buffer, 1, bytes_written, comp->
file) < bytes_written) {
304 SCLogError(
"fwrite failed: %s", strerror(errno));
346 if (PcapLogCloseFile(t,pl) < 0) {
363 PcapFileNameFree(pf);
367 if (PcapLogOpenFileCtx(pl) < 0) {
368 SCLogError(
"opening new pcap log file failed");
383 if (PacketIsTunnelChild(
p)) {
388 SCLogDebug(
"Setting pcap-log link type to %u", datalink);
395 struct bpf_program bpfp;
402 if (pl->
bpfp == NULL) {
403 FatalError(
"Failed to allocate memory for BPF filter, aborting");
414 if (!pl->pcap_open_err) {
416 pl->pcap_open_err =
true;
420 pl->pcap_open_err =
false;
428 if (comp->
file == NULL) {
429 if (errno != pl->fopen_err) {
430 SCLogError(
"Error opening file for compressed output: %s", strerror(errno));
431 pl->fopen_err = errno;
439 if (comp->pcap_buf_wrapper == NULL) {
446 if (!pl->pcap_open_err) {
448 pl->pcap_open_err =
true;
452 fclose(comp->pcap_buf_wrapper);
453 comp->pcap_buf_wrapper = NULL;
456 pl->pcap_open_err =
false;
459 uint64_t bytes_written = LZ4F_compressBegin(comp->lz4f_context,
461 if (LZ4F_isError(bytes_written)) {
462 SCLogError(
"LZ4F_compressBegin: %s", LZ4F_getErrorName(bytes_written));
465 if (fwrite(comp->
buffer, 1, bytes_written, comp->
file) < bytes_written) {
466 SCLogError(
"fwrite failed: %s", strerror(errno));
503 static inline int PcapWrite(
506 struct timeval current_dump;
507 gettimeofday(¤t_dump, NULL);
511 if (pcap_offline_filter(pl->
bpfp, pl->
h, data) == 0) {
512 SCLogDebug(
"Packet doesn't match filter, will not be logged.");
528 long in_size = ftell(comp->pcap_buf_wrapper);
530 SCLogError(
"ftell failed with: %s", strerror(errno));
533 uint64_t out_size = LZ4F_compressUpdate(comp->lz4f_context, comp->
buffer, comp->
buffer_size,
534 comp->
pcap_buf, (uint64_t)in_size, NULL);
535 if (LZ4F_isError(
len)) {
536 SCLogError(
"LZ4F_compressUpdate: %s", LZ4F_getErrorName(
len));
539 if (fseek(comp->pcap_buf_wrapper, 0, SEEK_SET) != 0) {
540 SCLogError(
"fseek failed: %s", strerror(errno));
543 if (fwrite(comp->
buffer, 1, out_size, comp->
file) < out_size) {
544 SCLogError(
"fwrite failed: %s", strerror(errno));
558 pl->last_pcap_dump = current_dump;
567 static int PcapLogSegmentCallback(
568 const Packet *
p,
TcpSegment *seg,
void *data,
const uint8_t *buf, uint32_t buflen)
581 const uint32_t total_len = pktlen + buflen;
585 if (expand_by % 4096 != 0) {
586 expand_by = expand_by - (expand_by % 4096) + 4096;
589 SCLogWarning(
"Failed to expand pcap-log buffer for segment "
598 MemBufferReset(pctx->
td->
buf);
602 PcapWrite(pctx->
tv, pctx->
td, (uint8_t *)pctx->
td->
buf->
buffer, total_len);
645 if (PacketIsTunnelChild(
p)) {
657 ret = PcapLogOpenFileCtx(pl);
668 if (PcapLogRotateFile(
tv, pl) < 0) {
684 if (PcapLogRotateFile(
tv, pl) < 0) {
707 if (PacketIsTCP(
p)) {
709 PcapLogDumpSegments(
tv,
td,
p);
719 if (PacketIsTunnelChild(
p)) {
732 if (PacketIsTunnelChild(
p)) {
747 SCLogDebug(
"pl->size_current %"PRIu64
", pl->size_limit %"PRIu64,
768 copy->prefix =
SCStrdup(pl->prefix);
769 if (
unlikely(copy->prefix == NULL)) {
775 copy->suffix = pl->suffix;
781 copy->use_ringbuffer = pl->use_ringbuffer;
782 copy->timestamp_format = pl->timestamp_format;
798 copy_comp->lz4f_prefs = comp->lz4f_prefs;
803 if (copy_comp->
buffer == NULL) {
804 SCLogError(
"SCMalloc failed: %s", strerror(errno));
812 SCLogError(
"SCMalloc failed: %s", strerror(errno));
821 if (copy_comp->pcap_buf_wrapper == NULL) {
822 SCLogError(
"SCFmemopen failed: %s", strerror(errno));
833 LZ4F_errorCode_t errcode =
834 LZ4F_createCompressionContext(©_comp->lz4f_context, 1);
835 if (LZ4F_isError(errcode)) {
836 SCLogError(
"LZ4F_createCompressionContext failed: %s", LZ4F_getErrorName(errcode));
837 fclose(copy_comp->pcap_buf_wrapper);
848 copy_comp->
file = NULL;
856 strlcpy(copy->dir, pl->dir,
sizeof(copy->dir));
858 for (
int i = 0; i < pl->filename_part_cnt && i <
MAX_TOKS; i++)
859 copy->filename_parts[i] = pl->filename_parts[i];
860 copy->filename_part_cnt = pl->filename_part_cnt;
869 #ifdef INIT_RING_BUFFER
870 static int PcapLogGetTimeOfFile(
const char *filename, uint64_t *secs,
876 int n = pcre2_match(pcre_timestamp_code, (PCRE2_SPTR8)filename, strlen(filename), 0, 0,
877 pcre_timestamp_match, NULL);
878 if (n != 2 && n != 4) {
885 copylen =
sizeof(buf);
886 if (pcre2_substring_copy_bynumber(pcre_timestamp_match, 1, (PCRE2_UCHAR8 *)buf, ©len) <
896 copylen =
sizeof(buf);
897 if (pcre2_substring_copy_bynumber(pcre_timestamp_match, 3, (PCRE2_UCHAR8 *)buf, ©len) <
911 char pattern[PATH_MAX];
913 SCLogInfo(
"Initializing PCAP ring buffer for %s/%s.",
914 pl->dir, pl->prefix);
916 strlcpy(pattern, pl->dir, PATH_MAX);
917 if (pattern[strlen(pattern) - 1] !=
'/') {
918 strlcat(pattern,
"/", PATH_MAX);
921 for (
int i = 0; i < pl->filename_part_cnt; i++) {
922 char *part = pl->filename_parts[i];
923 if (part == NULL || strlen(part) == 0) {
926 if (part[0] !=
'%' || strlen(part) < 2) {
927 strlcat(pattern, part, PATH_MAX);
932 SCLogError(
"Thread ID not allowed in ring buffer mode.");
936 snprintf(tmp, PATH_MAX,
"%"PRIu32, pl->thread_number);
937 strlcat(pattern, tmp, PATH_MAX);
941 strlcat(pattern,
"*", PATH_MAX);
944 SCLogError(
"Unsupported format character: %%%s", part);
949 strlcat(pattern, pl->prefix, PATH_MAX);
950 strlcat(pattern,
".*", PATH_MAX);
952 strlcat(pattern, pl->suffix, PATH_MAX);
954 char *basename = strrchr(pattern,
'/');
958 DIR *dir = opendir(pattern);
960 SCLogWarning(
"Failed to open directory %s: %s", pattern, strerror(errno));
965 struct dirent *entry = readdir(dir);
969 if (fnmatch(basename, entry->d_name, 0) != 0) {
976 if (!PcapLogGetTimeOfFile(entry->d_name, &secs, &usecs)) {
987 if (
PathMerge(path,
sizeof(path), pattern, entry->d_name) < 0)
1043 PcapFileNameFree(pf);
1059 static TmEcode PcapLogDataInit(
ThreadVars *t,
const void *initdata,
void **data)
1061 if (initdata == NULL) {
1062 SCLogDebug(
"Error getting context for LogPcap. \"initdata\" argument NULL");
1076 td->
pcap_log = PcapLogDataCopy(pl);
1083 FatalError(
"Pcap logging with multiple link type is not supported.");
1094 FatalError(
"Can't have multiple link types in pcap conditional mode.");
1097 SCLogWarning(
"Using multiple link types can result in invalid pcap output");
1133 #ifdef INIT_RING_BUFFER
1138 SCLogInfo(
"Unable to initialize ring buffer on this platform.");
1149 PcapLogOpenFileCtx(pl);
1159 dst->profile_open.total +=
src->profile_open.total;
1160 dst->profile_open.cnt +=
src->profile_open.cnt;
1162 dst->profile_close.total +=
src->profile_close.total;
1163 dst->profile_close.cnt +=
src->profile_close.cnt;
1165 dst->profile_write.total +=
src->profile_write.total;
1166 dst->profile_write.cnt +=
src->profile_write.cnt;
1168 dst->profile_rotate.total +=
src->profile_rotate.total;
1169 dst->profile_rotate.cnt +=
src->profile_rotate.cnt;
1171 dst->profile_handles.total +=
src->profile_handles.total;
1172 dst->profile_handles.cnt +=
src->profile_handles.cnt;
1174 dst->profile_lock.total +=
src->profile_lock.total;
1175 dst->profile_lock.cnt +=
src->profile_lock.cnt;
1177 dst->profile_unlock.total +=
src->profile_unlock.total;
1178 dst->profile_unlock.cnt +=
src->profile_unlock.cnt;
1180 dst->profile_data_size +=
src->profile_data_size;
1187 while ((pf =
TAILQ_FIRST(&pl->pcap_file_list)) != NULL) {
1190 PcapFileNameFree(pf);
1192 if (pl == g_pcap_data) {
1193 for (
int i = 0; i <
MAX_TOKS; i++) {
1194 if (pl->filename_parts[i] != NULL) {
1195 SCFree(pl->filename_parts[i]);
1208 pcap_freecode(pl->
bpfp);
1214 SCFree(pl->compression.buffer);
1215 if (pl->compression.pcap_buf_wrapper)
1216 fclose(pl->compression.pcap_buf_wrapper);
1217 SCFree(pl->compression.pcap_buf);
1218 LZ4F_errorCode_t errcode =
1219 LZ4F_freeCompressionContext(pl->compression.lz4f_context);
1220 if (LZ4F_isError(errcode)) {
1249 StatsMerge(g_pcap_data, pl);
1250 g_pcap_data->reported++;
1251 if (g_pcap_data->threads == g_pcap_data->reported)
1252 PcapLogProfilingDump(g_pcap_data);
1255 if (pl->reported == 0) {
1256 PcapLogProfilingDump(pl);
1261 if (pl != g_pcap_data) {
1262 PcapLogDataFree(pl);
1273 static int ParseFilename(
PcapLogData *pl,
const char *filename)
1280 size_t filename_len = 0;
1283 filename_len = strlen(filename);
1289 for (
int i = 0; i < (int)strlen(filename); i++) {
1291 SCLogError(
"invalid filename option. Max 2 %%-sign options");
1295 str[s++] = filename[i];
1297 if (filename[i] ==
'%') {
1308 if (i+1 < (
int)strlen(filename)) {
1310 SCLogError(
"invalid filename option. Max 2 %%-sign options");
1314 if (filename[i+1] !=
'n' && filename[i+1] !=
't' && filename[i+1] !=
'i') {
1316 "invalid filename option. Valid %%-sign options: %%n, %%i and %%t");
1320 str[1] = filename[i+1];
1332 SCLogError(
"Invalid filename for multimode. Need at least one %%-sign option");
1338 SCLogError(
"invalid filename option. Max 3 %%-sign options");
1350 for (
int i = 0; i < tok; i++) {
1351 if (toks[i] == NULL)
1355 pl->filename_parts[i] = toks[i];
1357 pl->filename_part_cnt = tok;
1361 for (
int x = 0; x <
MAX_TOKS; x++) {
1362 if (toks[x] != NULL)
1379 FatalError(
"A pcap-log instance is already active, only one can be enabled.");
1384 FatalError(
"Failed to allocate Memory for PcapLogData");
1388 if (pl->
h == NULL) {
1389 FatalError(
"Failed to allocate Memory for pcap header struct");
1406 pcre_timestamp_code =
1407 pcre2_compile((PCRE2_SPTR8)timestamp_pattern, PCRE2_ZERO_TERMINATED, 0, &en, &eo, NULL);
1408 if (pcre_timestamp_code == NULL) {
1409 PCRE2_UCHAR errbuffer[256];
1410 pcre2_get_error_message(en, errbuffer,
sizeof(errbuffer));
1412 "Failed to compile \"%s\" at offset %d: %s", timestamp_pattern, (
int)eo, errbuffer);
1414 pcre_timestamp_match = pcre2_match_data_create_from_pattern(pcre_timestamp_code, NULL);
1418 const char *filename = NULL;
1424 if (filename == NULL)
1427 if ((pl->prefix =
SCStrdup(filename)) == NULL) {
1435 const char *s_limit = NULL;
1437 if (s_limit != NULL) {
1439 SCLogError(
"Failed to initialize pcap output, invalid limit: %s", s_limit);
1443 SCLogInfo(
"pcap-log \"limit\" value of %"PRIu64
" assumed to be pre-1.2 "
1445 uint64_t size = pl->
size_limit * 1024 * 1024;
1448 FatalError(
"Fail to initialize pcap-log output, limit less than "
1449 "allowed minimum of %d bytes.",
1456 const char *s_mode = NULL;
1458 if (s_mode != NULL) {
1459 if (strcasecmp(s_mode,
"multi") == 0) {
1461 }
else if (strcasecmp(s_mode,
"normal") != 0) {
1462 FatalError(
"log-pcap: invalid mode \"%s\". Valid options: \"normal\""
1463 "or \"multi\" mode ",
1468 const char *s_dir = NULL;
1470 if (s_dir == NULL) {
1471 const char *log_dir = NULL;
1474 strlcpy(pl->dir, log_dir,
sizeof(pl->dir));
1479 s_dir,
sizeof(pl->dir));
1481 const char *log_dir = NULL;
1484 snprintf(pl->dir,
sizeof(pl->dir),
"%s/%s",
1488 struct stat stat_buf;
1489 if (stat(pl->dir, &stat_buf) != 0) {
1491 "supplied doesn't exist. Shutting down the engine",
1500 if (compression_str == NULL || strcmp(compression_str,
"none") == 0) {
1508 comp->pcap_buf_wrapper = NULL;
1510 }
else if (strcmp(compression_str,
"lz4") == 0) {
1520 SCLogError(
"SCMalloc failed: %s", strerror(errno));
1525 if (comp->pcap_buf_wrapper == NULL) {
1526 SCLogError(
"SCFmemopen failed: %s", strerror(errno));
1532 memset(&comp->lz4f_prefs,
'\0',
sizeof(comp->lz4f_prefs));
1533 comp->lz4f_prefs.frameInfo.blockSizeID = LZ4F_max4MB;
1534 comp->lz4f_prefs.frameInfo.blockMode = LZ4F_blockLinked;
1536 comp->lz4f_prefs.frameInfo.contentChecksumFlag = 1;
1538 comp->lz4f_prefs.frameInfo.contentChecksumFlag = 0;
1544 }
else if (lvl < 0) {
1550 comp->lz4f_prefs.compressionLevel = (int)lvl;
1554 LZ4F_errorCode_t errcode =
1555 LZ4F_createCompressionContext(&pl->compression.lz4f_context, 1);
1557 if (LZ4F_isError(errcode)) {
1558 SCLogError(
"LZ4F_createCompressionContext failed: %s", LZ4F_getErrorName(errcode));
1570 "lz4 output buffer.");
1577 pl->suffix =
".lz4";
1580 "in pcap-log, but suricata was not compiled with lz4 "
1582 PcapLogDataFree(pl);
1588 "compression format: %s",
1590 PcapLogDataFree(pl);
1594 SCLogInfo(
"Selected pcap-log compression method: %s",
1595 compression_str ? compression_str :
"none");
1598 if (s_conditional != NULL) {
1599 if (strcasecmp(s_conditional,
"alerts") == 0) {
1602 }
else if (strcasecmp(s_conditional,
"tag") == 0) {
1605 }
else if (strcasecmp(s_conditional,
"all") != 0) {
1606 FatalError(
"log-pcap: invalid conditional \"%s\". Valid options: \"all\", "
1607 "\"alerts\", or \"tag\" mode ",
1613 "Selected pcap-log conditional logging: %s", s_conditional ? s_conditional :
"all");
1616 if (ParseFilename(pl, filename) != 0)
1623 const char *max_number_of_files_s = NULL;
1625 if (max_number_of_files_s != NULL) {
1627 max_number_of_files_s) == -1) {
1629 "pcap-log output, invalid number of files limit: %s",
1630 max_number_of_files_s);
1632 }
else if (max_file_limit < 1) {
1633 FatalError(
"Failed to initialize pcap-log output, limit less than "
1634 "allowed minimum.");
1642 const char *ts_format = NULL;
1646 if (ts_format != NULL) {
1647 if (strcasecmp(ts_format,
"usec") == 0) {
1649 }
else if (strcasecmp(ts_format,
"sec") != 0) {
1650 SCLogError(
"log-pcap ts_format specified %s is invalid must be"
1651 " \"sec\" or \"usec\"",
1657 const char *use_stream_depth = NULL;
1661 if (use_stream_depth != NULL) {
1667 FatalError(
"log-pcap use_stream_depth specified is invalid must be");
1671 const char *honor_pass_rules = NULL;
1675 if (honor_pass_rules != NULL) {
1681 FatalError(
"log-pcap honor-pass-rules specified is invalid");
1690 if (
unlikely(output_ctx == NULL)) {
1691 FatalError(
"Failed to allocate memory for OutputCtx.");
1693 output_ctx->
data = pl;
1694 output_ctx->
DeInit = PcapLogFileDeInitCtx;
1697 result.
ctx = output_ctx;
1702 static void PcapLogFileDeInitCtx(
OutputCtx *output_ctx)
1704 if (output_ctx == NULL)
1713 PcapLogDataFree(pl);
1716 pcre2_code_free(pcre_timestamp_code);
1717 pcre2_match_data_free(pcre_timestamp_match);
1753 char file[PATH_MAX] =
"";
1758 ret = snprintf(file,
sizeof(file),
"%s.%" PRIu32
"%s", pl->prefix,
1761 ret = snprintf(file,
sizeof(file),
"%s.%" PRIu32
".%" PRIu32
"%s", pl->prefix,
1764 if (ret < 0 || (
size_t)ret >= PATH_MAX) {
1769 if (pl->filename_part_cnt > 0) {
1772 for (
int i = 0; i < pl->filename_part_cnt; i++) {
1773 if (pl->filename_parts[i] == NULL ||strlen(pl->filename_parts[i]) == 0)
1777 if (pl->filename_parts[i][0] ==
'%') {
1779 if (strlen(pl->filename_parts[i]) < 2)
1782 switch(pl->filename_parts[i][1]) {
1784 snprintf(
str,
sizeof(
str),
"%u", pl->thread_number);
1789 snprintf(
str,
sizeof(
str),
"%"PRIu64, (uint64_t)thread_id);
1797 snprintf(
str,
sizeof(
str),
"%" PRIu32
".%" PRIu32,
1805 strlcat(file, pl->filename_parts[i],
sizeof(file));
1808 strlcat(file, pl->suffix,
sizeof(file));
1813 ret = snprintf(file,
sizeof(file),
"%s.%u.%" PRIu32
"%s", pl->prefix,
1816 ret = snprintf(file,
sizeof(file),
"%s.%u.%" PRIu32
".%" PRIu32
"%s", pl->prefix,
1820 if (ret < 0 || (
size_t)ret >= PATH_MAX) {
1827 if (
PathMerge(path, PATH_MAX, pl->dir, file) < 0) {
1833 SCLogError(
"Error allocating memory. For filename");
1846 PcapFileNameFree(pf);
1859 static int profiling_pcaplog_enabled = 0;
1860 static int profiling_pcaplog_output_to_file = 0;
1861 static char *profiling_pcaplog_file_name = NULL;
1862 static const char *profiling_pcaplog_file_mode =
"a";
1864 static void FormatNumber(uint64_t num,
char *
str,
size_t size)
1867 snprintf(
str, size,
"%"PRIu64, num);
1868 else if (num < 1000000UL)
1869 snprintf(
str, size,
"%3.1fk", (
float)num/1000UL);
1870 else if (num < 1000000000UL)
1871 snprintf(
str, size,
"%3.1fm", (
float)num/1000000UL);
1873 snprintf(
str, size,
"%3.1fb", (
float)num/1000000000UL);
1878 char ticks_str[32] =
"n/a";
1879 char cnt_str[32] =
"n/a";
1880 char avg_str[32] =
"n/a";
1882 FormatNumber((uint64_t)
p->cnt, cnt_str,
sizeof(cnt_str));
1883 FormatNumber((uint64_t)
p->total, ticks_str,
sizeof(ticks_str));
1884 if (
p->cnt &&
p->total)
1885 FormatNumber((uint64_t)(
p->total/
p->cnt), avg_str,
sizeof(avg_str));
1887 fprintf(fp,
"%-28s %-10s %-10s %-10s\n",
name, cnt_str, avg_str, ticks_str);
1890 static void ProfileReport(FILE *fp,
const PcapLogData *pl)
1895 ProfileReportPair(fp,
"rotate (incl open/close)", &pl->
profile_rotate);
1901 static void FormatBytes(uint64_t num,
char *
str,
size_t size)
1904 snprintf(
str, size,
"%"PRIu64, num);
1905 else if (num < 1048576UL)
1906 snprintf(
str, size,
"%3.1fKiB", (
float)num/1000UL);
1907 else if (num < 1073741824UL)
1908 snprintf(
str, size,
"%3.1fMiB", (
float)num/1000000UL);
1910 snprintf(
str, size,
"%3.1fGiB", (
float)num/1000000000UL);
1913 static void DoDump(
const PcapLogData *pl, FILE *fp)
1916 fprintf(fp,
"\n\nOperation Cnt Avg ticks Total ticks\n");
1917 fprintf(fp,
"---------------------------- ---------- ---------- -----------\n");
1919 ProfileReport(fp, pl);
1926 fprintf(fp,
"\nOverall: %"PRIu64
" bytes written, average %d bytes per write.\n",
1929 fprintf(fp,
" PCAP data structure overhead: %"PRIuMAX
" per write.\n",
1930 (uintmax_t)
sizeof(
struct pcap_pkthdr));
1935 fprintf(fp,
" Size written: %s\n", bytes_str);
1938 uint64_t ticks_per_mib = 0, ticks_per_gib = 0;
1941 ticks_per_mib = total/mib;
1942 char ticks_per_mib_str[32] =
"n/a";
1943 if (ticks_per_mib > 0)
1944 FormatNumber(ticks_per_mib, ticks_per_mib_str,
sizeof(ticks_per_mib_str));
1945 fprintf(fp,
" Ticks per MiB: %s\n", ticks_per_mib_str);
1949 ticks_per_gib = total/gib;
1950 char ticks_per_gib_str[32] =
"n/a";
1951 if (ticks_per_gib > 0)
1952 FormatNumber(ticks_per_gib, ticks_per_gib_str,
sizeof(ticks_per_gib_str));
1953 fprintf(fp,
" Ticks per GiB: %s\n", ticks_per_gib_str);
1958 if (profiling_pcaplog_enabled == 0)
1961 if (profiling_pcaplog_output_to_file == 1) {
1962 FILE *fp = fopen(profiling_pcaplog_file_name, profiling_pcaplog_file_mode);
1964 SCLogError(
"failed to open %s: %s", profiling_pcaplog_file_name, strerror(errno));
1978 profiling_pcaplog_enabled = 1;
1979 SCLogInfo(
"pcap-log profiling enabled");
1982 if (filename != NULL) {
1983 const char *log_dir;
1986 profiling_pcaplog_file_name =
SCMalloc(PATH_MAX);
1987 if (
unlikely(profiling_pcaplog_file_name == NULL)) {
1991 snprintf(profiling_pcaplog_file_name, PATH_MAX,
"%s/%s", log_dir, filename);
1995 profiling_pcaplog_file_mode =
"a";
1997 profiling_pcaplog_file_mode =
"w";
2000 profiling_pcaplog_output_to_file = 1;
2001 SCLogInfo(
"pcap-log profiling output goes to %s (mode %s)",
2002 profiling_pcaplog_file_name, profiling_pcaplog_file_mode);