2021-04-01T18:34:09 root[7389] /usr/local/etc/rc.d/suricata: WARNING: failed to start suricata
1/4/2021 -- 19:31:36 - <Info> - Including configuration file installed_rules.yaml.1/4/2021 -- 19:31:36 - <Info> - Configuration node 'rule-files' redefined.1/4/2021 -- 19:31:36 - <Info> - Including configuration file custom.yaml../suricata: WARNING: failed to start suricata
OPNsense 21.7.a_314-amd64FreeBSD 12.1-RELEASE-p15-HBSDLibreSSL 3.2.5
Apr 1 17:33:38 OPNsense suricata[72140]: [100255] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 17:33:38 OPNsense suricata[72140]: [100255] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 17:37:16 OPNsense suricata[40561]: [100128] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 17:37:16 OPNsense suricata[40561]: [100128] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 17:44:59 OPNsense suricata[95863]: [100343] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 17:44:59 OPNsense suricata[95863]: [100343] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 18:34:09 OPNsense suricata[77466]: [100851] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 18:34:09 OPNsense suricata[77466]: [100851] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 19:31:36 OPNsense suricata[78420]: [100843] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 19:31:36 OPNsense suricata[78420]: [100843] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 19:37:02 OPNsense suricata[18973]: [100835] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 19:37:02 OPNsense suricata[18973]: [100835] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 19:37:54 OPNsense suricata[92966]: [100386] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 19:37:54 OPNsense suricata[92966]: [100386] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.Apr 1 19:38:12 OPNsense suricata[10120]: [100298] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 1 19:38:12 OPNsense suricata[10120]: [100298] <Error> -- [ERRCODE: SC_ERR_INVALID_VALUE(130)] - Hyperscan (hs) support for mpm-algo is not compiled into Suricata.
Updating OPNsense repository catalogue...OPNsense repository is up to date.All repositories are up to date.Checking integrity... done (0 conflicting)The most recent versions of packages are already installed
Apr 2 15:21:43 OPNsense suricata[31904]: [100315] <Notice> -- opened netmap:igb1/R from igb1: 0x3a3abb1a000Apr 2 15:21:43 OPNsense suricata[31904]: [100315] <Notice> -- opened netmap:igb1^ from igb1^: 0x3a3abb1a300Apr 2 15:21:43 OPNsense suricata[31904]: [101293] <Notice> -- opened netmap:igb1^ from igb1^: 0x3a3c247b000Apr 2 15:21:44 OPNsense suricata[31904]: [101293] <Notice> -- opened netmap:igb1/T from igb1: 0x3a3c247b300Apr 2 15:21:44 OPNsense suricata[31904]: [101296] <Notice> -- opened netmap:pppoe0/R from pppoe0: 0x3a3ecd66000Apr 2 15:21:44 OPNsense suricata[31904]: [101296] <Notice> -- opened netmap:pppoe0^ from pppoe0^: 0x3a3ecd66300Apr 2 15:21:44 OPNsense suricata[31904]: [101328] <Notice> -- opened netmap:pppoe0^ from pppoe0^: 0x3a401dfc000Apr 2 15:21:44 OPNsense suricata[31904]: [101328] <Notice> -- opened netmap:pppoe0/T from pppoe0: 0x3a401dfc300Apr 2 15:21:44 OPNsense suricata[31904]: [100851] <Notice> -- all 4 packet processing threads, 4 management threads initialized, engine started.Apr 2 15:22:58 OPNsense suricata[31904]: [100851] <Notice> -- rule reload startingApr 2 15:23:00 OPNsense suricata[31904]: [100851] <Error> -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'http_raw_cookie'.Apr 2 15:23:00 OPNsense suricata[31904]: [100851] <Error> -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "drop tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"SERVER-WEBAPP Multiple products DVR admin password leak attempt"; flow:to_server,established; content:"/device.rsp"; fast_pattern:only; http_uri; content:"uid="; http_raw_cookie; content:"cmd=list"; http_client_body; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service http; reference:cve,2018-9995; classtype:web-application-attack; sid:55839; rev:1;)" from file /usr/local/etc/suricata/opnsense.rules/snort_vrt.server-webapp.rules at line 100
2021-04-14T01:03:14 suricata[59758] [100259] <Error> -- [ERRCODE: SC_ERR_FATAL(171)] - Engine unable to disable detect thread - "W#01-igb1". Killing engine 2021-04-14T01:02:13 suricata[59758] [100259] <Notice> -- Signal Received. Stopping engine. 2021-04-14T00:59:57 suricata[59758] [100259] <Notice> -- all 4 packet processing threads, 4 management threads initialized, engine started. 2021-04-14T00:59:57 suricata[59758] [100336] <Notice> -- opened netmap:pppoe0/T from pppoe0: 0x753e7ffc300 2021-04-14T00:59:57 suricata[59758] [100336] <Notice> -- opened netmap:pppoe0^ from pppoe0^: 0x753e7ffc000 2021-04-14T00:59:57 suricata[59758] [100329] <Notice> -- opened netmap:pppoe0^ from pppoe0^: 0x753d2db1300 2021-04-14T00:59:57 suricata[59758] [100329] <Notice> -- opened netmap:pppoe0/R from pppoe0: 0x753d2db1000 2021-04-14T00:59:57 suricata[59758] [100327] <Notice> -- opened netmap:igb1/T from igb1: 0x753933fc300 2021-04-14T00:59:57 suricata[59758] [100327] <Notice> -- opened netmap:igb1^ from igb1^: 0x753933fc000 2021-04-14T00:59:57 suricata[59758] [100316] <Notice> -- opened netmap:igb1^ from igb1^: 0x7537e3d3300 2021-04-14T00:59:56 suricata[59758] [100316] <Notice> -- opened netmap:igb1/R from igb1: 0x7537e3d3000
Apr 14 00:59:55 OPNsense kernel: pflog0: promiscuous mode disabledApr 14 00:59:55 OPNsense kernel: pflog0: promiscuous mode enabledApr 14 00:59:55 OPNsense kernel: OKApr 14 00:59:56 OPNsense kernel: igb1: permanently promiscuous mode enabledApr 14 00:59:56 OPNsense kernel: igb1: link state changed to DOWNApr 14 00:59:56 OPNsense kernel: igb1_vlan2: link state changed to DOWNApr 14 00:59:56 OPNsense kernel: igb1_vlan3: link state changed to DOWNApr 14 00:59:57 OPNsense opnsense-devel[61802]: /usr/local/etc/rc.linkup: Hotplug event detected for XXXXXX(lan) but ignoring since interface is configured with static IP (XXXXXXX ::)Apr 14 00:59:57 OPNsense opnsense-devel[25342]: /usr/local/etc/rc.linkup: Hotplug event detected for XXXXXX(opt3) but ignoring since interface is configured with static IP (XXXXXXX ::)Apr 14 00:59:57 OPNsense kernel: 797.304698 [1130] generic_netmap_attach Emulated adapter for pppoe0 created (prev was NULL)Apr 14 00:59:57 OPNsense kernel: 797.313687 [1035] generic_netmap_dtor Emulated netmap adapter for pppoe0 destroyedApr 14 00:59:57 OPNsense kernel: pppoe0: permanently promiscuous mode enabledApr 14 00:59:57 OPNsense kernel: 797.324028 [1130] generic_netmap_attach Emulated adapter for pppoe0 created (prev was NULL)Apr 14 00:59:57 OPNsense kernel: 797.333117 [ 320] generic_netmap_register Emulated adapter for pppoe0 activatedApr 14 00:59:57 OPNsense opnsense-devel[61189]: /usr/local/etc/rc.linkup: Hotplug event detected for XXXXXXX(opt6) but ignoring since interface is configured with static IP (XXXXXXXX ::)Apr 14 00:59:57 OPNsense kernel: SHA256 12 23 34 56 78 AA BB CC DD EE FF AA EE AA EEApr 14 01:00:01 OPNsense kernel: igb1: link state changed to UPApr 14 01:00:01 OPNsense kernel: igb1_vlan2: link state changed to UPApr 14 01:00:01 OPNsense kernel: igb1_vlan3: link state changed to UPApr 14 01:00:01 OPNsense opnsense-devel[40612]: /usr/local/etc/rc.linkup: Hotplug event detected for XXXXXX(lan) but ignoring since interface is configured with static IP (XXXXXXX ::)Apr 14 01:00:01 OPNsense opnsense-devel[16932]: /usr/local/etc/rc.newwanip: IPv4 renewal is starting on 'igb1'Apr 14 01:00:01 OPNsense opnsense-devel[16932]: /usr/local/etc/rc.newwanip: On (IP address: XXXXXX) (interface: XXXXX[lan]) (real interface: igb1).Apr 14 01:00:01 OPNsense opnsense-devel[16932]: plugins_configure hosts ()
27 Apr 14 11:53:24 OPNsense suricata[28570]: [100221] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.otf' is checked but not set. Checked in 35719 and 0 other sigs 28 Apr 14 11:53:26 OPNsense suricata[28570]: [101286] <Notice> -- opened netmap:igb1/R from igb1: 0x662f9cde000 29 Apr 14 11:53:27 OPNsense suricata[28570]: [101286] <Notice> -- opened netmap:igb1^ from igb1^: 0x662f9cde300 30 Apr 14 11:53:27 OPNsense suricata[28570]: [101296] <Notice> -- opened netmap:igb1^ from igb1^: 0x66323dcf000 31 Apr 14 11:53:27 OPNsense suricata[28570]: [101296] <Notice> -- opened netmap:igb1/T from igb1: 0x66323dcf300 32 Apr 14 11:53:27 OPNsense suricata[28570]: [100221] <Notice> -- all 2 packet processing threads, 4 management threads initialized, engine started. 33 Apr 14 11:57:37 OPNsense suricata[28570]: [100221] <Notice> -- Signal Received. Stopping engine. 34 Apr 14 11:58:38 OPNsense suricata[28570]: [100221] <Error> -- [ERRCODE: SC_ERR_FATAL(171)] - Engine unable to disable detect thread - "W#01-igb1". Killing engine
187 igb1: link state changed to UP188 igb1_vlan2: link state changed to UP189 igb1_vlan3: link state changed to UP190 igb0: link state changed to UP191 pflog0: promiscuous mode enabled192 pflog0: promiscuous mode disabled193 pflog0: promiscuous mode enabled194 pflog0: promiscuous mode disabled195 pflog0: promiscuous mode enabled196 pflog0: promiscuous mode disabled197 pflog0: promiscuous mode enabled198 tun0: link state changed to UP199 tun0: changing name to 'wg0'200 pflog0: promiscuous mode disabled201 pflog0: promiscuous mode enabled202 pflog0: promiscuous mode disabled203 pflog0: promiscuous mode enabled204 pid 43540 (syslogd), jid 0, uid 0: exited on signal 11 (core dumped)205 pflog0: promiscuous mode disabled206 pflog0: promiscuous mode enabled207 pflog0: promiscuous mode disabled208 pflog0: promiscuous mode enabled209 [HBSD SEGVGUARD] [/usr/local/sbin/syslogd (5818)] Suspension expired.210 -> pid: 5818 ppid: 47253 p_pax: 0xa50<SEGVGUARD,ASLR,NOSHLIBRANDOM,NODISALLOWMAP32BIT>211 pflog0: promiscuous mode disabled
Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Notice> -- This is Suricata version 6.0.2 RELEASE running in SYSTEM modeApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- CPUs/cores online: 4Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Adding interface igb1 from config fileApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Adding interface igb1^ from config fileApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- 'default' server has 'request-body-minimal-inspect-size' set to 33713 and 'request-body-inspect-window' set to 4276 after randomization.Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- 'default' server has 'response-body-minimal-inspect-size' set to 39729 and 'response-body-inspect-window' set to 16683 after randomization.Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- SMB stream depth: 0Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Modbus request flood protection level: 500Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Modbus stream depth: 0Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Protocol detection and parser disabled for enip protocol.Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Protocol detection and parser disabled for DNP3.Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- Found an MTU of 1500 for 'igb1'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- Found an MTU of 1500 for 'igb1'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- Found an MTU of 1500 for 'igb1'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- Found an MTU of 1500 for 'igb1'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- preallocated 1000 hosts of size 104Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- host memory usage: 366144 bytes, maximum: 33554432Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Core dump size is unlimited.Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- Netmap: Setting IPS modeApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- preallocated 65535 defrag trackers of size 128Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- defrag memory usage: 9961344 bytes, maximum: 33554432Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- flow size 288, memcap allows for 466033 flows. Per hash row in perfect conditions 7Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "prealloc-sessions": 2048 (per thread)Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "memcap": 67108864Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "midstream" session pickups: disabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "async-oneside": disabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "checksum-validation": enabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream."inline": enabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "bypass": disabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream "max-synack-queued": 5Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream.reassembly "memcap": 268435456Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream.reassembly "depth": 1048576Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream.reassembly "toserver-chunk-size": 2660Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream.reassembly "toclient-chunk-size": 2480Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream.reassembly.raw: enabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- stream.reassembly "segment-prealloc": 2048Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- eve-log output device (regular) initialized: eve.jsonApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- enabling 'eve-log' module 'alert'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- enabling 'eve-log' module 'anomaly'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- enabling 'eve-log' module 'drop'Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- stats output device (regular) initialized: stats.logApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Info> -- Syslog output initializedApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Delayed detect disabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- pattern matchers: MPM: hs, SPM: hsApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- toclient-groups 1024Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- toserver-groups 1024Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- grouping: udp-whitelist (default) 53, 135, 5060Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- prefilter engines: MPMApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_uriApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_raw_uriApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_request_lineApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_client_bodyApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_response_lineApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_headerApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_headerApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_header_namesApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_header_namesApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_acceptApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_accept_encApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_accept_langApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_refererApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_connectionApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_content_lenApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_content_lenApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_content_typeApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_content_typeApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http.serverApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http.locationApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_protocolApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_protocolApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_startApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_startApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_raw_headerApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_raw_headerApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_methodApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_cookieApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_cookieApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file.magicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_hostApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http_raw_hostApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http2_header_nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for http2_headerApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for dnp3_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tls.sniApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tls.cert_issuerApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tls.cert_serialApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tls.cert_fingerprintApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ja3.hashApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ja3s.hashApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for dce_stub_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for dce_stub_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for smb_named_pipeApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh.protoApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh.protoApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh_softwareApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh_softwareApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh.hasshApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh.hassh.serverApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh.hassh.stringApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ssh.hassh.server.stringApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for file_dataApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for krb5_cnameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for krb5_snameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.methodApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.uriApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.protocolApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.protocolApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.methodApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.stat_msgApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.request_lineApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for sip.response_lineApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for rfb.nameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for snmp.communityApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for snmp.communityApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.connect.clientidApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.connect.usernameApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.connect.passwordApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.connect.willtopicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.connect.willmessageApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.publish.topicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.publish.messageApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.subscribe.topicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for mqtt.unsubscribe.topicApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for icmpv4.hdrApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tcp.hdrApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for udp.hdrApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for icmpv6.hdrApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ipv4.hdrApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for ipv6.hdrApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- IP reputation disabledApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/OPNsense.rulesApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- No rules loaded from OPNsense.rules.Apr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/botcc.rulesApr 14 12:59:29 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/emerging-exploit.rulesApr 14 12:59:30 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/compromised.rulesApr 14 12:59:30 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.browser-chrome.rulesApr 14 12:59:30 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.browser-firefox.rulesApr 14 12:59:30 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.browser-ie.rulesApr 14 12:59:30 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.exploit-kit.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.exploit.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- No rules loaded from snort_vrt.exploit.rules.Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.scan.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- No rules loaded from snort_vrt.scan.rules.Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.server-webapp.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Error> -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'http_raw_cookie'.Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Error> -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "drop tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"SERVER-WEBAPP Multiple products DVR admin password leak attempt"; flow:to_server,established; content:"/device.rsp"; fast_pattern:only; http_uri; content:"uid="; http_raw_cookie; content:"cmd=list"; http_client_body; metadata:policy balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, service http; reference:cve,2018-9995; classtype:web-application-attack; sid:55839; rev:1;)" from file /usr/local/etc/suricata/opnsense.rules/snort_vrt.server-webapp.rules at line 100Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.os-linux.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.os-mobile.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- Loading rule file: /usr/local/etc/suricata/opnsense.rules/snort_vrt.os-windows.rulesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Info> -- 14 rule files processed. 3949 rules successfully loaded, 1 rules failedApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Info> -- Threshold config parsed: 0 rule(s) foundApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tcp-packetApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for tcp-streamApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for udp-packetApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- using shared mpm ctx' for other-ipApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Info> -- 3949 signatures processed. 202 are IP-only rules, 389 are inspecting packet payload, 1365 inspect application layer, 0 are decoder event onlyApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Config> -- building signature grouping structure, stage 1: preprocessing rules... completeApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.CVE20157547.primer' is checked but not set. Checked in 2022547 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.IE7.NoRef.NoCookie' is checked but not set. Checked in 2024192 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.http.binary' is checked but not set. Checked in 2025195 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.http.javaclient' is checked but not set. Checked in 2017557 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'et.JavaArchiveOrClass' is checked but not set. Checked in 2017772 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.HB.Request.SI' is checked but not set. Checked in 2018378 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.pdf.in.http' is checked but not set. Checked in 2017790 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.ttf' is checked but not set. Checked in 35523 and 17 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.mht' is checked but not set. Checked in 49799 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.exe' is checked but not set. Checked in 18405 and 183 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.pdf' is checked but not set. Checked in 26539 and 3 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.emf' is checked but not set. Checked in 38773 and 3 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.swf' is checked but not set. Checked in 33272 and 2 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.jar' is checked but not set. Checked in 25302 and 6 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.cws' is checked but not set. Checked in 24670 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.zip' is checked but not set. Checked in 24669 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.jpeg' is checked but not set. Checked in 21510 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.elf' is checked but not set. Checked in 37435 and 3 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.lnk' is checked but not set. Checked in 45624 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.dat' is checked but not set. Checked in 40393 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.rtf' is checked but not set. Checked in 37277 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.application' is checked but not set. Checked in 36712 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.xls' is checked but not set. Checked in 35984 and 1 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Warning> -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'file.otf' is checked but not set. Checked in 35719 and 0 other sigsApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- TCP toserver: 173 port groups, 83 unique SGH's, 90 copiesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- TCP toclient: 52 port groups, 19 unique SGH's, 33 copiesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- UDP toserver: 39 port groups, 20 unique SGH's, 19 copiesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- UDP toclient: 9 port groups, 5 unique SGH's, 4 copiesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- OTHER toserver: 2 proto groups, 1 unique SGH's, 1 copiesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- OTHER toclient: 2 proto groups, 0 unique SGH's, 2 copiesApr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Unique rule groups: 128Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "toserver TCP packet": 26Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "toclient TCP packet": 8Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "toserver TCP stream": 65Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "toclient TCP stream": 16Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "toserver UDP packet": 20Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "toclient UDP packet": 5Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- Builtin MPM "other IP packet": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_uri (http)": 13Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_raw_uri (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_request_line (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_client_body (http)": 6Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_header (http)": 8Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient http_header (http)": 8Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_content_type (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient http_content_type (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_start (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient http_start (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver http_user_agent (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient http_stat_code (http)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver tls.sni (tls)": 1Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver dce_stub_data (smb)": 2Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient dce_stub_data (smb)": 2Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver dce_stub_data (dcerpc)": 2Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver file_data (smtp)": 10Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient file_data (http)": 10Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver file_data (smb)": 10Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient file_data (smb)": 10Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toserver file_data (http2)": 10Apr 14 12:59:31 OPNsense suricata[38494]: [100355] <Perf> -- AppLayer MPM "toclient file_data (http2)": 10Apr 14 12:59:33 OPNsense suricata[38494]: [100355] <Perf> -- Using 1 threads for interface igb1Apr 14 12:59:33 OPNsense suricata[38494]: [100355] <Info> -- Going to use 1 thread(s)Apr 14 12:59:33 OPNsense suricata[38494]: [100390] <Notice> -- opened netmap:igb1/R from igb1: 0x4e4d53fc000Apr 14 12:59:34 OPNsense suricata[38494]: [100390] <Notice> -- opened netmap:igb1^ from igb1^: 0x4e4d53fc300Apr 14 12:59:34 OPNsense suricata[38494]: [100355] <Perf> -- Using 1 threads for interface igb1^Apr 14 12:59:34 OPNsense suricata[38494]: [100355] <Info> -- Going to use 1 thread(s)Apr 14 12:59:34 OPNsense suricata[38494]: [100406] <Notice> -- opened netmap:igb1^ from igb1^: 0x4e4ea7fc000Apr 14 12:59:34 OPNsense suricata[38494]: [100406] <Notice> -- opened netmap:igb1/T from igb1: 0x4e4ea7fc300Apr 14 12:59:34 OPNsense suricata[38494]: [100355] <Config> -- using 1 flow manager threadsApr 14 12:59:34 OPNsense suricata[38494]: [100355] <Config> -- using 1 flow recycler threadsApr 14 12:59:34 OPNsense suricata[38494]: [100355] <Notice> -- all 2 packet processing threads, 4 management threads initialized, engine started.Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Notice> -- Signal Received. Stopping engine.Apr 14 12:59:55 OPNsense suricata[38494]: [100402] <Perf> -- 0 new flows, 0 established flows were timed out, 0 flows in closed stateApr 14 12:59:55 OPNsense suricata[38494]: [100355] <Info> -- time elapsed 21.392sApr 14 12:59:55 OPNsense suricata[38494]: [100414] <Perf> -- 52 flows processedApr 14 12:59:55 OPNsense suricata[38494]: [100390] <Perf> -- (W#01-igb1) Kernel: Packets 359, dropped 0, bytes 42618Apr 14 12:59:55 OPNsense suricata[38494]: [100406] <Perf> -- (W#01-igb1^) Kernel: Packets 726, dropped 0, bytes 692065Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Info> -- Alerts: 0Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Perf> -- ippair memory usage: 382144 bytes, maximum: 16777216Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Perf> -- host memory usage: 366144 bytes, maximum: 33554432Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Info> -- cleaning up signature grouping structure... completeApr 14 12:59:55 OPNsense suricata[38494]: [100355] <Notice> -- Stats for 'igb1': pkts: 359, drop: 0 (0.00%), invalid chksum: 0Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Notice> -- Stats for 'igb1^': pkts: 726, drop: 0 (0.00%), invalid chksum: 0Apr 14 12:59:55 OPNsense suricata[38494]: [100355] <Perf> -- Cleaning up Hyperscan global scratchApr 14 12:59:55 OPNsense suricata[38494]: [100355] <Perf> -- Clearing Hyperscan database cache