pfelk / pfelk

pfSense/OPNsense + Elastic Stack
https://pfelk.github.io/pfelk/
Other
1.07k stars 192 forks source link

PFSENSE SURICATA problems #287

Closed mrahmatellah closed 3 years ago

mrahmatellah commented 3 years ago

Hello,

I have done the same steps as you descibed (https://github.com/pfelk/pfelk/blob/main/install/configuration.md),

FIREWALL DHCP UNBOUNd HAPROXY work but suricata don't

EVE Syslog Output Facility: AUTH EVE Syslog Output Priority: NOTICE

can't found this 2 line on suricata

image

(PFSENSE PELK)

revere521 commented 3 years ago

have a look at #276

Also verify the suricata config here https://github.com/pfelk/pfelk/blob/main/install/configuration.md#four-suricata---optional and here https://github.com/pfelk/pfelk/wiki/How-To:-Suricata-on-pfSense

mrahmatellah commented 3 years ago

updates:

I change the port of Step 4c (from 5141) to 5040 ( as mentionned on /etc/pfelk/conf.d/01-inputs.conf) id => "pfelk-suricata" type .... port => 5040 (!!!)

after this modification, event coming ... so if anyone meet the same problem be sure that you have tyhe same port on the 2 configuration