Hello,
Thank you so much for your reply.
I did tcpdump. The contents of the log files are as follows:
# cat /var/log/suricata/suricata.log
[864 - Suricata-Main] 2023-10-28 02:04:12 Notice: suricata: This is Suricata version 7.0.0 RELEASE running in SYSTEM mode
[864 - Suricata-Main] 2023-10-28 02:04:12 Info: cpu: CPUs/cores online: 2
[864 - Suricata-Main] 2023-10-28 02:04:12 Info: af-packet: Setting IPS mode
[864 - Suricata-Main] 2023-10-28 02:04:12 Info: exception-policy: master exception-policy set to: auto
[864 - Suricata-Main] 2023-10-28 02:04:13 Info: ioctl: CLIENT: MTU 1500
[864 - Suricata-Main] 2023-10-28 02:04:13 Info: ioctl: SERVER: MTU 1500
[864 - Suricata-Main] 2023-10-28 02:04:13 Info: logopenfile: fast output device (regular) initialized: fast.log
[864 - Suricata-Main] 2023-10-28 02:04:13 Info: logopenfile: eve-log output device (regular) initialized: eve.json
[864 - Suricata-Main] 2023-10-28 02:04:13 Info: logopenfile: stats output device (regular) initialized: stats.log
[864 - Suricata-Main] 2023-10-28 02:04:14 Info: detect: 1 rule files processed. 41733 rules successfully loaded, 0 rules failed
[864 - Suricata-Main] 2023-10-28 02:04:14 Info: threshold-config: Threshold config parsed: 0 rule(s) found
[864 - Suricata-Main] 2023-10-28 02:04:15 Info: detect: 41736 signatures processed. 1497 are IP-only rules, 5391 are inspecting packet payload, 34641 inspect application layer, 108 are decoder event only
[864 - Suricata-Main] 2023-10-28 02:04:21 Info: af-packet: CLIENT: AF_PACKET IPS mode activated CLIENT->SERVER
[864 - Suricata-Main] 2023-10-28 02:04:21 Info: runmodes: CLIENT: creating 2 threads
[864 - Suricata-Main] 2023-10-28 02:04:22 Info: af-packet: SERVER: AF_PACKET IPS mode activated SERVER->CLIENT
[864 - Suricata-Main] 2023-10-28 02:04:22 Info: runmodes: SERVER: creating 2 threads
[867 - W#01-SERVER] 2023-10-28 02:04:22 Info: ioctl: SERVER: MTU 1500
[867 - W#01-SERVER] 2023-10-28 02:04:22 Info: ioctl: CLIENT: MTU 1500
[868 - W#02-SERVER] 2023-10-28 02:04:22 Info: ioctl: SERVER: MTU 1500
[868 - W#02-SERVER] 2023-10-28 02:04:22 Info: ioctl: CLIENT: MTU 1500
[864 - Suricata-Main] 2023-10-28 02:04:22 Info: unix-manager: unix socket '/var/run/suricata/suricata-command.socket'
[864 - Suricata-Main] 2023-10-28 02:04:22 Info: unix-manager: created socket directory /var/run/suricata/
[864 - Suricata-Main] 2023-10-28 02:04:22 Notice: threads: Threads created -> W: 4 FM: 1 FR: 1 Engine started.
[864 - Suricata-Main] 2023-10-28 02:06:06 Notice: suricata: Signal Received. Stopping engine.
[864 - Suricata-Main] 2023-10-28 02:06:07 Info: suricata: time elapsed 105.439s
[864 - Suricata-Main] 2023-10-28 02:06:08 Info: counters: Alerts: 0
[864 - Suricata-Main] 2023-10-28 02:06:08 Notice: device: CLIENT: packets: 179, drops: 0 (0.00%), invalid chksum: 0
[864 - Suricata-Main] 2023-10-28 02:06:08 Notice: device: SERVER: packets: 108, drops: 0 (0.00%), invalid chksum: 0
And:
# cat /var/log/suricata/fast.log
#
And:
The eve.json file.
What is your opinion?