Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug] Duplicate File Logs for Emulations

Open
#73 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
52/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
python
Domain
backend

Research direction

Start in BaseEmulation and inspect how the console and file handlers are attached to self.elogger. Reproduce the issue through SWAT Shell with an OOTB emulation, then review its file in logs/. Done means each self.elogger.* call appears only once in the respective emulation log.

Written by the indexing model from the issue text.

Description

bug

🐛 Bug Report

Describe the bug

When running an emulation, there is a separate console and file handler set to self.elogger within BaseEmulation. This allows emulations to use a secondary logger to separate logging. The log files written to are within the logs/ directory where the log file name represents the emulation.

There is a bug currently that is duplicating logs within each respective emulation log file.

Steps to reproduce

Steps to reproduce the behavior:

  1. Start SWAT Shell
  2. Authenticate with OAuth credentials
  3. Run any OOTB emulation
  4. Review log file in logs/

Expected behavior

The logging should only be happening once per self.elogger.* call.

Screenshots

2023-08-12 15:15:32,486 - initial_access.gmail_phishing_form_link - INFO - Created Google Form: 17b0DwhmBY0Ihv_q85zuZj2fJdPYOFQuiuhuZvbGSgAg (gmail_phishing_form_link.py:47)
2023-08-12 15:15:32,486 - initial_access.gmail_phishing_form_link - INFO - Created Google Form: 17b0DwhmBY0Ihv_q85zuZj2fJdPYOFQuiuhuZvbGSgAg (gmail_phishing_form_link.py:47)
2023-08-12 15:15:32,488 - initial_access.gmail_phishing_form_link - INFO - Created email with Google Form link (gmail_phishing_form_link.py:59)
2023-08-12 15:15:32,488 - initial_access.gmail_phishing_form_link - INFO - Created email with Google Form link (gmail_phishing_form_link.py:59)
2023-08-12 15:15:33,333 - initial_access.gmail_phishing_form_link - INFO - Sent email to [email protected] from [email protected] (gmail_phishing_form_link.py:65)
2023-08-12 15:15:33,333 - initial_access.gmail_phishing_form_link - INFO - Sent email to [email protected] from [email protected] (gmail_phishing_form_link.py:65)

SWAT version

0.0.1

Checklist

Please ensure you've completed the following tasks:

  • I've described the bug in as much detail as possible
  • I've provided steps to reproduce the bug
  • I've added any relevant screenshots or other information
Dominant language
Python
Stars
169
Forks
8
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from elastic/SWAT

All issues in elastic/SWAT

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.