2021-11-28T21:51:07 suricata[69591] [100651] <Notice> -- all 1 packet processing threads, 4 management threads initialized, engine started.
See Services -> Intrusion Detection -> Administration and there the tab "Alerts"
If you don't really need it, it's imho currently like asking for trouble to run suricata (IPS). If interfaces go south, turn it off...
PS: VLANs need promisc mode enabled for suricata
organisation: ORG-DP125-RIPEorg-name: Dmitriy Panchenkoorg-type: OTHERaddress: Shirokaya street 1, bld. 4, apt. 15address: 127282, Moscow, Russian Federation
If you are protecting your server you'd want it monitoring your WAN connection not necessarily your vlan.
Also have you created you policies?
Quote from: FullyBorked on December 01, 2021, 03:02:41 pmIf you are protecting your server you'd want it monitoring your WAN connection not necessarily your vlan. I don't want to monitor my family network other than basic protective measures. Too much noise. Just the network with the public servers.Quote from: FullyBorked on December 01, 2021, 03:02:41 pmAlso have you created you policies? Not yet, just activated IDS. Any good link to start?Thanks,Patrick