We are running Suricata 4.1.8 with the ET PRO ruleset. Alerts with IPv4 are fine, but IPv6 alerts always have the source and destination IP the same. Here is an example (I have anonymized the IP). Any thoughts as to why?
sensor id: 0 event id: 135 event second: 1599745673 event microsecond: 711144
sig id: 2018959 gen id: 1 revision: 4 classification: 24
priority: 1 ip source: xxxx:4de0:ac19::1:44:44 ip destination: xxxx:4de0:ac19::1:44:44
src port: 80 dest port: 59713 protocol: 6 impact_flag: 0 blocked: 0