OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: jimjohn on April 27, 2021, 02:43:40 PM

Title: No alerts in Suricata (after update to v21.1.5?)
Post by: jimjohn on April 27, 2021, 02:43:40 PM
Hi,

although all the rules seem to load appropriately and some packages are tracked (see screenshot), I do not see any alerts in Suricata. What could I have done wrong?

I am fairly sure that I must have seen some alerts, my Fritz!Repeater is sending IPv6 junk and it got alerted a couple of days ago reliably. However, since the update to v21.1.5 the policies seem broken.

The interfaces seem to be okay (packages are captured, but nothing is visible in the logs ...).

First the policies went down (no drop anymore, only alerts) and now everything seems broken. Do you have something for me that I can start investigating?
Title: Re: No alerts in Suricata (after update to v21.1.5?)
Post by: jimjohn on April 28, 2021, 02:08:08 PM
Anyone?  :-[ :-[ :-[ :-\ :-\ :-\