Describe the bug
When using the containerized version of Suricata (5.0.3) monitoring two interfaces (br0 & wg0) following instructions at https://github.com/boostchicken/udm-utilities/tree/master/suricata, the UTM daemon crashes at first eve_alert.log generation.
Describe the bug When using the containerized version of Suricata (5.0.3) monitoring two interfaces (br0 & wg0) following instructions at
https://github.com/boostchicken/udm-utilities/tree/master/suricata
, the UTM daemon crashes at firsteve_alert.log
generation.To Reproduce Steps to reproduce the behavior:
pkill suricata
5 Connect to UDM via WireGuardcurl -A "BlackSun" www.somedomain.tld
Expected behavior An IPS alert is generated in Alerts and Events. This indeed happens but it is soon followed by a UTM crash.
UDM Information
Additional context Any suggestion is welcome.