Suricata cannot detect attack traffic going to the server

Can you add more context to your setup? What version are you using, what config file, what ruleset, how do you start/run Suricata?
Do you run it in IDS or IPS mode? If in IDS mode, did you ensure that the traffic forwarding is working, so that you see the traffic mirrored to the Suricata instance?