Trouble with suricata promiscuous mode


I have enabled promiscuous mode on my interface and set “disable-promisc” to “no” in suricata.yml.

However, I am only able to see the network connections to and from the host and not the whole subnet.

Any help would be appreciated.



How does the machine running Suricata get network traffic?
Can you see the network traffic if you run tcpdump on the interface where the traffic is expected.