Hey there i need recelenty install suricata on ubuntu, its working fine things happeing inside the network are getting inside suricata perfect.
the thing is i have a mikrotik and i configure sniffer to send traffic to suricata.
i used this awesome guide
but i cannot resolve the issue about this.
if i made a tcpdump im seeing all the traffic coming from mikrotik but when i try to start suricata with the mode that supposed to read all that traffic.
root@suricata:/etc/suricata# trafr -s | suricata -c /etc/suricata/suricata.yaml -r -
11/5/2021 – 20:21:19 - - [ERRCODE: SC_ERR_INITIALIZATION(45)] - ERROR: Pcap file does not exist
inside suricata.yaml i put yes in the part about pcap.log but still same error.
Thanks anyone in advanced