OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: gctwnl on April 19, 2023, 10:38:09 am

Title: How can I check my Suricata actually works? (Deciso 22.10.2)
Post by: gctwnl on April 19, 2023, 10:38:09 am
I would like to use (for instance) the https://secure.eicar.org/eicar.com link to check if my Suricata setup works as it is running (Non-IPS) but I'm not seeing anything in logging that convinces me it is doing much. I am using the Free ET Telemetry setup. The widget shows "Last event: Feb 26" but I'd like to set up a notification for when an event happens and I can only test if that even notification works if I can trigger an event.
Title: Re: How can I check my Suricata actually works? (Deciso 22.10.2)
Post by: gctwnl on April 21, 2023, 12:56:58 am
https://forum.opnsense.org/index.php?topic=31461.msg151830#msg151830 has the answer. I actually forgot I had asked this already but I forgot I already had.