{\rtf1\ansi\ansicpg1252\cocoartf2759 \cocoatextscaling0\cocoaplatform0{\fonttbl\f0\fswiss\fcharset0 Helvetica;} {\colortbl;\red255\green255\blue255;} {\*\expandedcolortbl;;} \margl1440\margr1440\vieww11520\viewh8400\viewkind0 \pard\tx720\tx1440\tx2160\tx2880\tx3600\tx4320\tx5040\tx5760\tx6480\tx7200\tx7920\tx8640\pardirnatural\partightenfactor0 \f0\fs24 \cf0 [771 - Suricata-Main] 2024-02-18 08:21:01 Info: threshold-config: Threshold config parsed: 0 rule(s) found\ [771 - Suricata-Main] 2024-02-18 08:21:01 Info: detect: 43754 signatures processed. 1422 are IP-only rules, 5054 are inspecting packet payload, 36765 inspect application layer, 108 are decoder event only\ [771 - Suricata-Main] 2024-02-18 08:21:09 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 08:21:09 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [771 - Suricata-Main] 2024-02-18 08:21:09 Info: runmodes: en0: creating 1 thread\ [7939 - W#01-en0] 2024-02-18 08:21:09 Info: pcap: en0: running in 'auto' checksum mode. Detection of interface state will require 1000 packets\ [7939 - W#01-en0] 2024-02-18 08:21:09 Info: ioctl: en0: MTU 1500\ [7939 - W#01-en0] 2024-02-18 08:21:09 Info: pcap: en0: snaplen set to 1524\ [7939 - W#01-en0] 2024-02-18 08:21:09 Info: output-streaming: LogTcpDataLog is now set up\ [7939 - W#01-en0] 2024-02-18 08:21:09 Info: output-streaming: LogTcpDataLog is now set up\ [771 - Suricata-Main] 2024-02-18 08:21:09 Info: unix-manager: unix socket '/usr/local/var/run/suricata/suricata-command.socket'\ [771 - Suricata-Main] 2024-02-18 08:21:09 Notice: threads: Threads created -> W: 1 FM: 1 FR: 1 Engine started.\ [771 - Suricata-Main] 2024-02-18 08:21:09 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 08:21:09 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [7939 - W#01-en0] 2024-02-18 08:22:37 Info: checksum: No packets with invalid checksum, assuming checksum offloading is NOT used\ [771 - Suricata-Main] 2024-02-18 08:37:50 Notice: suricata: Signal Received. Stopping engine.\ [771 - Suricata-Main] 2024-02-18 08:37:51 Info: suricata: time elapsed 2369.829s\ [7939 - RX#01-en0] 2024-02-18 08:37:52 Info: pcap: en0: packets 14266, bytes 5059054\ [7939 - RX#01-en0] 2024-02-18 08:37:52 Info: pcap: en0: pcap total:14267 recv:14267 drop:0 (0.0%)\ [771 - Suricata-Main] 2024-02-18 08:37:52 Info: counters: Alerts: 112\ [771 - Suricata-Main] 2024-02-18 08:37:52 Notice: device: en0: packets: 14266, drops: 0 (0.00%), invalid chksum: 0\ [771 - Suricata-Main] 2024-02-18 08:37:57 Notice: suricata: Signal Received. Stopping engine.\ [771 - Suricata-Main] 2024-02-18 08:37:58 Info: suricata: time elapsed 1008.819s\ [7939 - W#01-en0] 2024-02-18 08:37:59 Info: pcap: en0: packets 6909, bytes 3190515\ [7939 - W#01-en0] 2024-02-18 08:37:59 Info: pcap: en0: pcap total:6911 recv:6911 drop:0 (0.0%)\ [771 - Suricata-Main] 2024-02-18 08:37:59 Info: counters: Alerts: 14\ [771 - Suricata-Main] 2024-02-18 08:37:59 Notice: device: en0: packets: 6909, drops: 0 (0.00%), invalid chksum: 0\ [259 - Suricata-Main] 2024-02-18 08:38:24 Notice: suricata: This is Suricata version 7.0.3 RELEASE running in SYSTEM mode\ [259 - Suricata-Main] 2024-02-18 08:38:24 Info: cpu: CPUs/cores online: 12\ [259 - Suricata-Main] 2024-02-18 08:38:24 Info: suricata: Setting engine mode to IDS mode by default\ [259 - Suricata-Main] 2024-02-18 08:38:24 Info: exception-policy: master exception-policy set to: auto\ [259 - Suricata-Main] 2024-02-18 08:38:24 Info: ioctl: en0: MTU 1500\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: conf: Running in live mode, activating unix socket\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: logopenfile: fast output device (regular) initialized: /usr/local/var/log/suricata/fast.log\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: logopenfile: eve-log output device (regular) initialized: eve.json\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: output-json-dnp3: DNP3 log sub-module initialized.\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: logopenfile: stats output device (regular) initialized: stats.log\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: output-filestore: forcing filestore of all files\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: log-tcp-data: opening logfile\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: logopenfile: tcp-data output device (regular) initialized: tcp-data.log\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: log-tcp-data: opening logfile\ [771 - Suricata-Main] 2024-02-18 08:38:24 Info: logopenfile: http-body-data output device (regular) initialized: http-data.log\ [771 - Suricata-Main] 2024-02-18 08:38:24 Warning: runmodes: lua support not compiled in. Reconfigure/recompile with lua(jit) and its development files installed to add lua support.\ [771 - Suricata-Main] 2024-02-18 08:38:25 Warning: detect: No rule files match the pattern signatures.rules\ [771 - Suricata-Main] 2024-02-18 08:38:25 Info: detect: 2 rule files processed. 43751 rules successfully loaded, 0 rules failed, 0\ [771 - Suricata-Main] 2024-02-18 08:38:25 Info: threshold-config: Threshold config parsed: 0 rule(s) found\ [771 - Suricata-Main] 2024-02-18 08:38:25 Info: detect: 43754 signatures processed. 1422 are IP-only rules, 5054 are inspecting packet payload, 36765 inspect application layer, 108 are decoder event only\ [771 - Suricata-Main] 2024-02-18 08:38:33 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 08:38:33 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [771 - Suricata-Main] 2024-02-18 08:38:33 Info: runmodes: en0: creating 1 thread\ [2307 - W#01-en0] 2024-02-18 08:38:33 Info: pcap: en0: running in 'auto' checksum mode. Detection of interface state will require 1000 packets\ [2307 - W#01-en0] 2024-02-18 08:38:33 Info: ioctl: en0: MTU 1500\ [2307 - W#01-en0] 2024-02-18 08:38:33 Info: pcap: en0: snaplen set to 1524\ [2307 - W#01-en0] 2024-02-18 08:38:33 Info: output-streaming: LogTcpDataLog is now set up\ [2307 - W#01-en0] 2024-02-18 08:38:33 Info: output-streaming: LogTcpDataLog is now set up\ [771 - Suricata-Main] 2024-02-18 08:38:33 Info: unix-manager: unix socket '/usr/local/var/run/suricata/suricata-command.socket'\ [771 - Suricata-Main] 2024-02-18 08:38:33 Notice: threads: Threads created -> W: 1 FM: 1 FR: 1 Engine started.\ [771 - Suricata-Main] 2024-02-18 08:38:33 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 08:38:33 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [2307 - W#01-en0] 2024-02-18 08:40:55 Info: checksum: No packets with invalid checksum, assuming checksum offloading is NOT used\ [771 - Suricata-Main] 2024-02-18 11:38:36 Notice: suricata: Signal Received. Stopping engine.\ [771 - Suricata-Main] 2024-02-18 11:38:36 Info: suricata: time elapsed 10803.394s\ [2307 - W#01-en0] 2024-02-18 11:38:37 Info: pcap: en0: packets 122009, bytes 47748676\ [2307 - W#01-en0] 2024-02-18 11:38:37 Info: pcap: en0: pcap total:122010 recv:122010 drop:0 (0.0%)\ [771 - Suricata-Main] 2024-02-18 11:38:37 Info: counters: Alerts: 212\ [771 - Suricata-Main] 2024-02-18 11:38:38 Notice: device: en0: packets: 122009, drops: 0 (0.00%), invalid chksum: 0\ [259 - Suricata-Main] 2024-02-18 11:51:11 Notice: suricata: This is Suricata version 7.0.3 RELEASE running in SYSTEM mode\ [259 - Suricata-Main] 2024-02-18 11:51:11 Info: cpu: CPUs/cores online: 12\ [259 - Suricata-Main] 2024-02-18 11:51:11 Info: suricata: Setting engine mode to IDS mode by default\ [259 - Suricata-Main] 2024-02-18 11:51:11 Info: exception-policy: master exception-policy set to: auto\ [259 - Suricata-Main] 2024-02-18 11:51:11 Info: ioctl: en0: MTU 1500\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: conf: Running in live mode, activating unix socket\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: logopenfile: fast output device (regular) initialized: /usr/local/var/log/suricata/fast.log\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: logopenfile: eve-log output device (regular) initialized: eve.json\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: output-json-dnp3: DNP3 log sub-module initialized.\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: logopenfile: stats output device (regular) initialized: stats.log\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: output-filestore: forcing filestore of all files\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: log-tcp-data: opening logfile\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: logopenfile: tcp-data output device (regular) initialized: tcp-data.log\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: log-tcp-data: opening logfile\ [771 - Suricata-Main] 2024-02-18 11:51:11 Info: logopenfile: http-body-data output device (regular) initialized: http-data.log\ [771 - Suricata-Main] 2024-02-18 11:51:11 Warning: runmodes: lua support not compiled in. Reconfigure/recompile with lua(jit) and its development files installed to add lua support.\ [771 - Suricata-Main] 2024-02-18 11:51:12 Warning: detect: No rule files match the pattern signatures.rules\ [771 - Suricata-Main] 2024-02-18 11:51:12 Info: detect: 2 rule files processed. 43747 rules successfully loaded, 0 rules failed, 0\ [771 - Suricata-Main] 2024-02-18 11:51:12 Info: threshold-config: Threshold config parsed: 0 rule(s) found\ [771 - Suricata-Main] 2024-02-18 11:51:12 Info: detect: 43750 signatures processed. 1418 are IP-only rules, 5054 are inspecting packet payload, 36765 inspect application layer, 108 are decoder event only\ [771 - Suricata-Main] 2024-02-18 11:51:19 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 11:51:19 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [771 - Suricata-Main] 2024-02-18 11:51:19 Info: runmodes: en0: creating 1 thread\ [7939 - W#01-en0] 2024-02-18 11:51:19 Info: pcap: en0: running in 'auto' checksum mode. Detection of interface state will require 1000 packets\ [7939 - W#01-en0] 2024-02-18 11:51:19 Info: ioctl: en0: MTU 1500\ [7939 - W#01-en0] 2024-02-18 11:51:19 Info: pcap: en0: snaplen set to 1524\ [7939 - W#01-en0] 2024-02-18 11:51:19 Info: output-streaming: LogTcpDataLog is now set up\ [7939 - W#01-en0] 2024-02-18 11:51:19 Info: output-streaming: LogTcpDataLog is now set up\ [771 - Suricata-Main] 2024-02-18 11:51:19 Info: unix-manager: unix socket '/usr/local/var/run/suricata/suricata-command.socket'\ [771 - Suricata-Main] 2024-02-18 11:51:19 Notice: threads: Threads created -> W: 1 FM: 1 FR: 1 Engine started.\ [771 - Suricata-Main] 2024-02-18 11:51:19 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 11:51:19 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [7939 - W#01-en0] 2024-02-18 11:53:48 Info: checksum: No packets with invalid checksum, assuming checksum offloading is NOT used\ [771 - Suricata-Main] 2024-02-18 11:56:45 Notice: suricata: Signal Received. Stopping engine.\ [771 - Suricata-Main] 2024-02-18 11:56:45 Info: suricata: time elapsed 326.034s\ [7939 - W#01-en0] 2024-02-18 11:56:46 Info: pcap: en0: packets 1776, bytes 555983\ [7939 - W#01-en0] 2024-02-18 11:56:46 Info: pcap: en0: pcap total:1780 recv:1780 drop:0 (0.0%)\ [771 - Suricata-Main] 2024-02-18 11:56:46 Info: counters: Alerts: 3\ [771 - Suricata-Main] 2024-02-18 11:56:47 Notice: device: en0: packets: 1776, drops: 0 (0.00%), invalid chksum: 0\ [259 - Suricata-Main] 2024-02-18 12:16:16 Notice: suricata: This is Suricata version 7.0.3 RELEASE running in SYSTEM mode\ [259 - Suricata-Main] 2024-02-18 12:16:16 Info: cpu: CPUs/cores online: 12\ [259 - Suricata-Main] 2024-02-18 12:16:16 Info: suricata: Setting engine mode to IDS mode by default\ [259 - Suricata-Main] 2024-02-18 12:16:16 Info: exception-policy: master exception-policy set to: auto\ [259 - Suricata-Main] 2024-02-18 12:16:16 Info: ioctl: en0: MTU 1500\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: conf: Running in live mode, activating unix socket\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: logopenfile: fast output device (regular) initialized: /usr/local/var/log/suricata/fast.log\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: logopenfile: eve-log output device (regular) initialized: eve.json\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: output-json-dnp3: DNP3 log sub-module initialized.\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: logopenfile: stats output device (regular) initialized: stats.log\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: output-filestore: forcing filestore of all files\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: log-tcp-data: opening logfile\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: logopenfile: tcp-data output device (regular) initialized: tcp-data.log\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: log-tcp-data: opening logfile\ [771 - Suricata-Main] 2024-02-18 12:16:16 Info: logopenfile: http-body-data output device (regular) initialized: http-data.log\ [771 - Suricata-Main] 2024-02-18 12:16:16 Warning: runmodes: lua support not compiled in. Reconfigure/recompile with lua(jit) and its development files installed to add lua support.\ [771 - Suricata-Main] 2024-02-18 12:16:17 Warning: detect: No rule files match the pattern signatures.rules\ [771 - Suricata-Main] 2024-02-18 12:16:17 Info: detect: 2 rule files processed. 43747 rules successfully loaded, 0 rules failed, 0\ [771 - Suricata-Main] 2024-02-18 12:16:18 Info: threshold-config: Threshold config parsed: 0 rule(s) found\ [771 - Suricata-Main] 2024-02-18 12:16:18 Info: detect: 43750 signatures processed. 1418 are IP-only rules, 5054 are inspecting packet payload, 36765 inspect application layer, 108 are decoder event only\ [771 - Suricata-Main] 2024-02-18 12:16:25 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 12:16:25 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [771 - Suricata-Main] 2024-02-18 12:16:25 Info: runmodes: en0: creating 1 thread\ [7939 - W#01-en0] 2024-02-18 12:16:25 Info: pcap: en0: running in 'auto' checksum mode. Detection of interface state will require 1000 packets\ [7939 - W#01-en0] 2024-02-18 12:16:25 Info: ioctl: en0: MTU 1500\ [7939 - W#01-en0] 2024-02-18 12:16:25 Info: pcap: en0: snaplen set to 1524\ [7939 - W#01-en0] 2024-02-18 12:16:25 Info: output-streaming: LogTcpDataLog is now set up\ [7939 - W#01-en0] 2024-02-18 12:16:25 Info: output-streaming: LogTcpDataLog is now set up\ [771 - Suricata-Main] 2024-02-18 12:16:25 Info: unix-manager: unix socket '/usr/local/var/run/suricata/suricata-command.socket'\ [771 - Suricata-Main] 2024-02-18 12:16:25 Notice: threads: Threads created -> W: 1 FM: 1 FR: 1 Engine started.\ [771 - Suricata-Main] 2024-02-18 12:16:25 Error: hugepages: unable to open /sys/devices/system/node/\ [771 - Suricata-Main] 2024-02-18 12:16:25 Error: hugepages: failed to obtain number of NUMA nodes in the system\ [7939 - W#01-en0] 2024-02-18 12:17:06 Info: checksum: No packets with invalid checksum, assuming checksum offloading is NOT used}