"Suricata and ClamAV has nothig to do with Sandbox. Sandboxing means the file is executed on a sandboxed system and the system calls are checked against anomalies"
THis type of integration os to complex for , requires too much resources for the OPNSense project.Or Am I wrong ?What can be done is to send files from suricata to cuckoo, with no bidirecitonal integration.