I’m new to Suricata (and networking in general)
I would like to know how (if possible) to detect non-ip protocols, for instance GOOSE.
I have a pcap with GOOSE packets (among ip packets)
When I set a simple rule:
alert ip any any -> any any …
All ip packets are detected, non-ip packets (GOOSE in my case) are not.
What should I do?
Thanks in advance for your help