i finally fixed it on centos a dedicated server but on vps(ubuntu22 suricata 6.0.13) there is some problem maybe like port mirroring of host or promisc mode of network interface
fast.log is null at all and only i get eve.log output without any alert and drop based on rules
eve.log:
{“timestamp”:“2023-06-28T00:34:28.993934+0330”,“flow_id”:573770299091598,“event_type”:“dns”,“src_ip”:“10.0.143.250”,“src_port”:64690,“dest_ip”:“1.0.0.1”,“dest_port”:53,“proto”:“UDP”,“dns”:{“type”:“query”,“id”:42501,“rrname”:“play.google.com”,“rrtype”:“A”,“tx_id”:0,“opcode”:0}}
{“timestamp”:“2023-06-28T00:34:29.001929+0330”,“flow_id”:573770299091598,“event_type”:“dns”,“src_ip”:“10.0.143.250”,“src_port”:64690,“dest_ip”:“1.0.0.1”,“dest_port”:53,“proto”:“UDP”,“dns”:{“version”:2,“type”:“answer”,“id”:42501,“flags”:“8180”,“qr”:true,“rd”:true,“ra”:true,“opcode”:0,“rrname”:“play.google.com”,“rrtype”:“A”,“rcode”:“NOERROR”,“answers”:[{“rrname”:“play.google.com”,“rrtype”:“A”,“ttl”:294,“rdata”:“142.251.39.110”}],“grouped”:{“A”:[“142.251.39.110”]}}}
{“timestamp”:“2023-06-28T00:34:29.048370+0330”,“flow_id”:2192146188477823,“event_type”:“tls”,“src_ip”:“10.0.110.235”,“src_port”:45828,“dest_ip”:“216.58.214.10”,“dest_port”:443,“proto”:“TCP”,“tls”:{“sni”:“pubsub.googleapis.com”,“version”:“TLS 1.3”,“ja3”:{},“ja3s”:{}}}
{“timestamp”:“2023-06-28T00:34:29.134818+0330”,“flow_id”:2048664216065805,“event_type”:“tls”,“src_ip”:“10.0.90.50”,“src_port”:38536,“dest_ip”:“216.58.214.10”,“dest_port”:443,“proto”:“TCP”,“tls”:{“sni”:“pubsub.googleapis.com”,“version”:“TLS 1.3”,“ja3”:{},“ja3s”:{}}}