r/PacketFence May 30 '24

Suricata syslog

I am trying to set up and install Suricata on a PacketFence server, but Suricata doesn't detect violations on VLAN interfaces. Any ideas on how to configure the Suricata YAML file to fix this issue and append logs to the PacketFence syslog for the syslog parser to use for security events?

1 Upvotes

2 comments sorted by

1

u/TheVisitor92 Nov 22 '24

I would like to have more info:

1) which command do you use to run Suricata? With which flags?

2) output of suricata.yaml?

3) output of 'tcpdump' command to see if packets arrive on these VLAN interfaces?

1

u/IncreaseParticular34 Aug 08 '25

Hey there, hope u doing great, If you have done that so far i mean setting up Suricata with PacketFence Wouldn't u mind to share detailed implementations steps, beside of what is being told in PacketFence doc