I noticed that my suricata setup might not be recording http events correctly. When i make a tcpdump against the mirrored traffic i can see some HTTP requests that are not being replicated as “HTTP events” in Suricata logs.
please provide the Suricata version you are using, how you run it and the config file.
Did you run the capture as a pcap against Suricata as well and still not seeing the http events?
I am using Suricata version 6.0.10, running against some mirrored traffic with af-packet. I can´t send the config file because it has sensible information.
As I said please also post the stats.log to get an idea if there are actual other events besides netflow. Ideally two stats.log to see how the stats progress between two time slots.
What it seems is that some events that should be logged as HTTP events are not being classified as that but instead only “netflow events”. It is hard to analyse with greater detail, but the example above should have appeared as an HTTP event but that did not happened
There is no “instead” a traffic can produce multiple events with just one flow. So you could see an alert, flow and http event from the same traffic.
To further analyse, record this traffic with tcpdump or other tools and produce a pcap file and run this against suricata to see if the event shows up in that case.