Replying to myself again.
I see this in the documentation (https://docs.opnsense.org/manual/reporting_traffic.html):
I have Suricata enabled. So I guess that's what's going on? When using IPS, the traffic disappears from these reporting graphs just as well as they disappear from the exporter into Prometheus...?
Bit disappointing if I'm forced to choose between one or the other.
I see this in the documentation (https://docs.opnsense.org/manual/reporting_traffic.html):
QuoteWhen an interface doesn't report traffic and you are certain there should be any, make sure to check if you have any services enabled that use netmap (zero copy) support on the selected interface (such as IPS and Sensei). When zero copy is used, packets won't by copied in the kernel in which case bpf can't read from the usual in memory buffer.
I have Suricata enabled. So I guess that's what's going on? When using IPS, the traffic disappears from these reporting graphs just as well as they disappear from the exporter into Prometheus...?
Bit disappointing if I'm forced to choose between one or the other.
"