We are running Suricata as a service and using af-packet mode. We would also like to specify a BPF.
I know that I can do it with by launching Suricata manually and putting the BPF on the command line.
I see that there is a known issue that the bpf-filter cannot be set in the suricata.yaml file (BPF filter file with af_packet not functioning)
I don’t see an obvious way to set this in the /etc/default/suricata file
Is there a way to specify the BPF filter when launching as a service? I can always make a new service with the correct command line, but it does not seem to be so nice.
Is there a way to get the desired effect while using a service ?