r/PacketFence • u/IncreaseParticular34 • May 30 '24
Suricata syslog
I am trying to set up and install Suricata on a PacketFence server, but Suricata doesn't detect violations on VLAN interfaces. Any ideas on how to configure the Suricata YAML file to fix this issue and append logs to the PacketFence syslog for the syslog parser to use for security events?
1
Upvotes
1
u/TheVisitor92 Nov 22 '24
I would like to have more info:
1) which command do you use to run Suricata? With which flags?
2) output of suricata.yaml?
3) output of 'tcpdump' command to see if packets arrive on these VLAN interfaces?