No alerts in Suricata (after update to v21.1.5?)

Started by jimjohn, April 27, 2021, 02:43:40 PM

Previous topic - Next topic
Hi,

although all the rules seem to load appropriately and some packages are tracked (see screenshot), I do not see any alerts in Suricata. What could I have done wrong?

I am fairly sure that I must have seen some alerts, my Fritz!Repeater is sending IPv6 junk and it got alerted a couple of days ago reliably. However, since the update to v21.1.5 the policies seem broken.

The interfaces seem to be okay (packages are captured, but nothing is visible in the logs ...).

First the policies went down (no drop anymore, only alerts) and now everything seems broken. Do you have something for me that I can start investigating?