Jumping in on this older post because I'm curious how your project evolved. Have you tried using some of the newer OPNsense plug-ins for threat detection or logging since then? I've had good results combining Suricata with better dashboard alerts, but I'm always looking for better setups. Would be great to hear what direction you ended up taking or if you're still building it out.
"