Skip to content

Rita does not detect new logs after the first import (v5.0.8) #34

@Mohammad-Mirasadollahi

Description

@Mohammad-Mirasadollahi

Hi

The first time I use the following command, RITA analyzes all my data and shows it to me. There's no problem in this part. But when I want to run this command from the second time onwards, it always tells me that "[!] all files were previously imported." However, new data is created in my log path, and I have checked that the log files are being updated, but RITA keeps giving me this error.

Command: rita import --database=mydb6 --logs=/opt/zeek/logs/current --rolling

Error: "[!] all files were previously imported."

Is this a bug, or am I doing something wrong? Because I didn't have this issue in the previous version, but this version gives me this message.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions