{"timestamp":"2024-02-21T08:46:28.328325-0800","flow_id":1126978883909981,"in_iface":"igb1^","event_type":"drop","src_ip":"50.xxx.xxx.xxx","src_port":63309,"dest_ip":"142.xxx.xxx.xxx","dest_port":443,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_server","drop":{"len":109,"tos":0,"ttl":63,"ipid":3499,"udplen":89,"reason":"applayer error"}}{"timestamp":"2024-02-21T08:46:28.329080-0800","flow_id":1131185437371657,"in_iface":"igb1^","event_type":"drop","src_ip":"50.xxx.xxx.xxx","src_port":35884,"dest_ip":"142.xxx.xxx.xxx","dest_port":443,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_server","drop":{"len":107,"tos":0,"ttl":63,"ipid":42478,"udplen":87,"reason":"applayer error"}}{"timestamp":"2024-02-21T08:46:28.330264-0800","flow_id":1126978883909981,"in_iface":"igb1","event_type":"drop","src_ip":"142.xxx.xxx.xxx","src_port":443,"dest_ip":"50.xxx.xxx.xxx","dest_port":63309,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_client","drop":{"len":1278,"tos":0,"ttl":57,"ipid":0,"udplen":1258,"reason":"flow drop"}}{"timestamp":"2024-02-21T08:46:28.331800-0800","flow_id":1131185437371657,"in_iface":"igb1","event_type":"drop","src_ip":"142.xxx.xxx.xxx","src_port":443,"dest_ip":"50.xxx.xxx.xxx","dest_port":35884,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_client","drop":{"len":1278,"tos":0,"ttl":57,"ipid":0,"udplen":1258,"reason":"flow drop"}}{"timestamp":"2024-02-21T08:46:28.349475-0800","flow_id":1219019499694066,"in_iface":"igb1^","event_type":"drop","src_ip":"50.xxx.xxx.xxx","src_port":49147,"dest_ip":"172.xxx.xxx.xxx","dest_port":443,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_server","drop":{"len":109,"tos":0,"ttl":63,"ipid":19617,"udplen":89,"reason":"applayer error"}}{"timestamp":"2024-02-21T08:46:28.353369-0800","flow_id":1219019499694066,"in_iface":"igb1","event_type":"drop","src_ip":"172.xxx.xxx.xxx","src_port":443,"dest_ip":"50.xxx.xxx.xxx","dest_port":49147,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_client","drop":{"len":1278,"tos":0,"ttl":57,"ipid":0,"udplen":1258,"reason":"flow drop"}}{"timestamp":"2024-02-21T08:46:28.391428-0800","flow_id":1399075579550517,"in_iface":"igb1^","event_type":"drop","src_ip":"50.xxx.xxx.xxx","src_port":43720,"dest_ip":"142.xxx.xxx.xxx","dest_port":443,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_server","drop":{"len":101,"tos":0,"ttl":63,"ipid":25591,"udplen":81,"reason":"applayer error"}}{"timestamp":"2024-02-21T08:46:28.397087-0800","flow_id":1399075579550517,"in_iface":"igb1","event_type":"drop","src_ip":"142.xxx.xxx.xxx","src_port":443,"dest_ip":"50.xxx.xxx.xxx","dest_port":43720,"proto":"UDP","pkt_src":"wire/pcap","direction":"to_client","drop":{"len":1278,"tos":128,"ttl":58,"ipid":0,"udplen":1258,"reason":"flow drop"}}
exception-policy: ignore
Use /usr/local/opnsense/service/templates/OPNsense/IDS/custom.yamlThis file makes the changes persistent across reboots and other Suricata config changes.