Im currently having some problems with a fresh installation of Ubuntu 22.04.1 LTS and Suricata 6.0.9. I installed everything from scratch, with two network interfaces, one for management and one with a port mirror from a switch. This setup was working before on Ubuntu 18 and an older version of Suricata.
My problem is that im not getting alerts on the fast.log file and the eve.json seems to only be getting UDP packets. I checked suricata-start.log and suricata.log but found no errors.
Im not an expert on suricata nor linux, but do you think that there could be something wrong with my configuration or the way operation system is configured?
Shouldnt something be in the 163 IPv4 packets, something that could trigger an alert with ET/free or at least something on the eve.json that is not UDP traffic?
What could be the next steps to try to identify the problem?
The UDP protocols include DHCP (Suricata will process/analyze these) and other protocols not processed by Suricata.
At this point, I’d suggest looking at the port mirror infra to see if it’s mirroring the expected traffic which I presume is your intranet in an East/West (wholly within your intranet) or North/South (intranet <-> internet) or a combination thereof.
I’ll check the port mirror on the switch and the whole configuration and the whole configuration of the hyperv system and mirror network on the hyperv.
The port mirror configuration had beed working for quite some time, its a full mirror of a switch to a single port, that its connected to a dedicated network interface on a hyperv server.