My interfaces are configured in the attachment. I have Intel EM0 and IGB0-IGB3 physical NICs. I was under the impression the Intel NICs are better at dealing with Suricata and VLANs?
1) I have set Suricata to my actual hardware interfaces in the interfaces section. Now I am not getting any visibility into which vlan is having an alert, even though the vlan interface shows in the alert. Do I enable both the actual hardware interfaces and the vlans?
2) I am not running IPS at this time. I would assume that if I enable IPS my rules better be spot on or I am going to start blocking good traffic correct?
3) I am now seeing this in the log: 2021-08-05T10:27:15 suricata[82213] [100427] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.Netwire.HB' is checked but not set. Checked in 2018283 and 0 other sigs. Am I missing a Suricata option for this?