{"timestamp":"2018-03-06T12:07:40.571052+0100","flow_id":28971542295690,"in_iface":"vmx0","event_type":"drop","src_ip":"192.168.254.250","src_port":57828,"dest_ip":"13.107.4.50","dest_port":80,"proto":"TCP","drop":{"len":305,"tos":2,"ttl":127,"ipid":20877,"tcpseq":1321765378,"tcpack":3104282439,"tcpwin":8212,"syn":false,"ack":true,"psh":true,"rst":false,"urg":false,"fin":false,"tcpres":0,"tcpurgp":0},"alert":{"action":"blocked","gid":1,"signature_id":2020573,"rev":2,"signature":"ET CURRENT_EVENTS INFO .exe download with no referer (noalert)","category":"Potentially Bad Traffic","severity":2}}{"timestamp":"2018-03-06T12:07:40.841859+0100","flow_id":786608068284868,"in_iface":"vmx1+","event_type":"drop","src_ip":"192.168.200.253","src_port":45951,"dest_ip":"13.107.4.50","dest_port":80,"proto":"TCP","drop":{"len":383,"tos":0,"ttl":64,"ipid":0,"tcpseq":3535207936,"tcpack":641069320,"tcpwin":517,"syn":false,"ack":true,"psh":true,"rst":false,"urg":false,"fin":false,"tcpres":0,"tcpurgp":0},"alert":{"action":"blocked","gid":1,"signature_id":2020573,"rev":2,"signature":"ET CURRENT_EVENTS INFO .exe download with no referer (noalert)","category":"Potentially Bad Traffic","severity":2}}{"timestamp":"2018-03-06T12:07:41.274817+0100","flow_id":28971542295690,"in_iface":"vmx0","event_type":"drop","src_ip":"192.168.254.250","src_port":57828,"dest_ip":"13.107.4.50","dest_port":80,"proto":"TCP","drop":{"len":356,"tos":2,"ttl":127,"ipid":20879,"tcpseq":1321765643,"tcpack":3104283110,"tcpwin":8209,"syn":false,"ack":true,"psh":true,"rst":false,"urg":false,"fin":false,"tcpres":0,"tcpurgp":0},"alert":{"action":"blocked","gid":1,"signature_id":2020573,"rev":2,"signature":"ET CURRENT_EVENTS INFO .exe download with no referer (noalert)","category":"Potentially Bad Traffic","severity":2}}{"timestamp":"2018-03-06T12:07:41.295349+0100","flow_id":786608068284868,"in_iface":"vmx1+","event_type":"drop","src_ip":"192.168.200.253","src_port":45951,"dest_ip":"13.107.4.50","dest_port":80,"proto":"TCP","drop":{"len":434,"tos":0,"ttl":64,"ipid":0,"tcpseq":3535208267,"tcpack":641069863,"tcpwin":517,"syn":false,"ack":true,"psh":true,"rst":false,"urg":false,"fin":false,"tcpres":0,"tcpurgp":0},"alert":{"action":"blocked","gid":1,"signature_id":2020573,"rev":2,"signature":"ET CURRENT_EVENTS INFO .exe download with no referer (noalert)","category":"Potentially Bad Traffic","severity":2}}{"timestamp":"2018-03-06T12:18:42.785185+0100","flow_id":2400770460837,"in_iface":"vmx0+","event_type":"alert","src_ip":"87.78.182.200","src_port":80,"dest_ip":"192.168.254.6","dest_port":44013,"proto":"TCP","alert":{"action":"allowed","gid":1,"signature_id":2260002,"rev":1,"signature":"SURICATA Applayer Detect protocol only one direction","category":"Generic Protocol Command Decode","severity":3},"http":{"length":1448},"app_proto":"http"}
Mar 6 12:01:06 OPNsense suricata[2522]: [100327] <Notice> -- all 4 packet processing threads, 4 management threads initialized, engine started.Mar 6 12:18:42 OPNsense suricata[2522]: [1:2260002:1] SURICATA Applayer Detect protocol only one direction [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 87.78.182.200:80 -> 192.168.254.6:44013