bammv / sguil

Sguil client for NSM
GNU General Public License v3.0
213 stars 74 forks source link

Transcript (force new) option results in hang and/or crash #43

Open dougburks opened 7 years ago

dougburks commented 7 years ago

Unlike #42, this issue does NOT appear to be limited to the first 2 minutes after Sguil starts.

Pivoting to transcript seems to work fine when using the normal transcript option or when choosing the "Transcript (force new)" option on a new alert where I haven't pivoted to pcap previously. However, if I choose the "Transcript (force new)" option for a TCP stream that I've pivoted to before, I get one of two behaviors:

  1. The transcript window hangs at "Merging results": screen shot 2016-10-21 at 11 20 52 am

OR

  1. sguild crashes:

screen shot 2016-10-21 at 11 28 21 am

screen shot 2016-10-21 at 11 28 37 am

Have you seen this issue before?

Thanks!