root@OPNsense:/var/log/suricata # tail -f suricata_20231101.log<173>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="2"] [100106] <Notice> -- This is Suricata version 6.0.15 RELEASE running in SYSTEM mode<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="3"] [100106] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol sip enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="4"] [100106] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol rfb enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="5"] [100106] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol mqtt enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="6"] [100106] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol rdp enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="7"] [100106] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68727 - [meta sequenceId="8"] [100106] <Warning> -- [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - App-Layer protocol http2 enable status not set, so enabling by default. This behavior will change in Suricata 7, so please update your config. See ticket #4744 for more details.<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68748 - [meta sequenceId="9"] [100123] <Warning> -- [ERRCODE: SC_WARN_DEPRECATED(203)] - Found deprecated eve-log.alert app-layer flag "http", enabling metadata.app-layer<172>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68748 - [meta sequenceId="10"] [100123] <Warning> -- [ERRCODE: SC_WARN_DEPRECATED(203)] - Found deprecated eve-log.alert app-layer flag "tls", enabling metadata.app-layer<173>1 2023-11-01T05:42:58+00:00 OPNsense.localdomain suricata 68748 - [meta sequenceId="11"] [100123] <Notice> -- all 2 packet processing threads, 4 management threads initialized, engine started.
drop http any any -> any any (msg:"OPNsense test eicar virus"; content:"|58 35 4f 21 50 25 40 41 50 5b 34 5c 50 5a 58 35 34 28 50 5e 29 37 43 43 29 37 7d 24 45 49 43 41 52 2d 53 54 41 4e 44 41 52 44 2d 41 4e 54 49 56 49 52 55 53 2d 54 45 53 54 2d 46 49 4c 45 21 24 48 2b 48 2a|"; fast_pattern; reference:url,www.eicar.org/anti_virus_test_file.htm; classtype:bad-unknown; sid:2023110201; rev:1;)drop http any any -> any any (msg:"OPNsense test-2 eicar virus"; content:"|4F 50 4E 73 65 6E 73 65|"; fast_pattern; reference:url,www.eicar.org/anti_virus_test_file.htm; classtype:bad-unknown; sid:2023110202; rev:1;)