<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[IDS&#x2F;IPS]]></title><description><![CDATA[Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.]]></description><link>https://forum.netgate.com/category/53</link><generator>RSS for Node</generator><lastBuildDate>Tue, 12 May 2026 03:58:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/category/53.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 May 2026 13:37:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[pfsense 26.03-RELEASE (amd64) running Suricata keeps crashing.]]></title><description><![CDATA[I was able to resolve the issue by reinstalling suricata package in pfsense.
]]></description><link>https://forum.netgate.com/topic/200662/pfsense-26.03-release-amd64-running-suricata-keeps-crashing.</link><guid isPermaLink="true">https://forum.netgate.com/topic/200662/pfsense-26.03-release-amd64-running-suricata-keeps-crashing.</guid><dc:creator><![CDATA[pvanderlaat]]></dc:creator><pubDate>Sun, 10 May 2026 13:37:52 GMT</pubDate></item><item><title><![CDATA[PHP Fatal error:  preg_replace()]]></title><description><![CDATA[<p dir="auto">Checking to see if I should create a bug report.  I searched and didn't find related discussion.</p>
<p dir="auto">Trying to navigate to Active Rules for an interface yields a blank (white) page.</p>
<p dir="auto">I have a Netgate 4200 MAX, 26.03-RELEASE (amd64).</p>
<p dir="auto">In Global Settings I have Snort VRT with code, Enable ET Open, Enable OpenAppID + Text Rules, Enable FEODO Tracker Botnet C2 IP Rules</p>
<p dir="auto">Services / Snort Interface Settings / PORT1WAN - Categories</p>
<ul>
<li>Resolve Flowbits</li>
<li>Use IPS Policy : Security<br />
Mode : Policy</li>
</ul>
<p dir="auto">Services / Snort Interface Settings / PORT1WAN - Rules</p>
<ul>
<li>Trying to view the Available Rule Categories, selecting Active Rules causes a momentary spin, then a blank page.</li>
</ul>
<p dir="auto">Then on the dashboard there is an error report link:</p>
<pre><code>Crash report begins.  Anonymous machine information:

amd64
16.0-CURRENT
FreeBSD 16.0-CURRENT #36 plus-RELENG_26_03-n256531-4923e82e59d1: Fri Mar 20 18:22:49 UTC 2026     root@pfsense-build-release-amd64-1.eng.atx.netgate.com:/var/jenkins/workspace/pfSense-Plus-snapshots-26_03-main/obj/amd64/TVcqnR7U/var/jenkins/workspace/pfSe

Crash report details:

PHP Errors:
[09-May-2026 11:35:01 US/Central] PHP Fatal error:  preg_replace(): Cannot use output buffering in output buffering display handlers in /usr/local/www/csrf/csrf-magic.php on line 163
Stack trace:
#0 /usr/local/www/csrf/csrf-magic.php(163): preg_replace()
#1 [internal function]: csrf_ob_handler()
#2 {main}

No FreeBSD crash data found.
</code></pre>
]]></description><link>https://forum.netgate.com/topic/200660/php-fatal-error-preg_replace</link><guid isPermaLink="true">https://forum.netgate.com/topic/200660/php-fatal-error-preg_replace</guid><dc:creator><![CDATA[mtrade]]></dc:creator><pubDate>Sat, 09 May 2026 17:11:29 GMT</pubDate></item><item><title><![CDATA[Does Snort Inline Blocking Effect All Interfaces?]]></title><description><![CDATA[<p dir="auto">One thing I've been confused about as I dive into Snort more in pfSense is the blocking modes. In most cases I'd prefer to have inline since it can stop packets before any get to the destination, however, inline mode is described in a lot of posts as being in between the host stack and the "physical interface".</p>
<p dir="auto">I'm curious if enabling this impacts more VLANs or if it just impacts the selected VLAN I have Snort running on in this environment.</p>
<p dir="auto">Any ideas?</p>
<p dir="auto">On an additional note, does this change require a reboot or anything along those lines?</p>
]]></description><link>https://forum.netgate.com/topic/200645/does-snort-inline-blocking-effect-all-interfaces</link><guid isPermaLink="true">https://forum.netgate.com/topic/200645/does-snort-inline-blocking-effect-all-interfaces</guid><dc:creator><![CDATA[planedrop]]></dc:creator><pubDate>Thu, 07 May 2026 03:01:47 GMT</pubDate></item><item><title><![CDATA[SNORT]]></title><description><![CDATA[<p dir="auto">After upgrade to v25.11.1 my console is filled with log entries from SNORT. I have turned off logging but still getting large influx of messages</p>
]]></description><link>https://forum.netgate.com/topic/200576/snort</link><guid isPermaLink="true">https://forum.netgate.com/topic/200576/snort</guid><dc:creator><![CDATA[BobL4002]]></dc:creator><pubDate>Wed, 22 Apr 2026 18:19:20 GMT</pubDate></item><item><title><![CDATA[Suricata 7.0.8_13 Crash on 26.03]]></title><description><![CDATA[@SteveITS
I'm not a bug hunter but I wanted to report some findings which might help with troubleshooting this issue.
I have two 6100s [26.03-RELEASE] - one with a single WAN Legacy interface in Suricata, the other with two WAN Legacy interfaces in Suricata.
On the assumption that perhaps it might have been a misconfiguration issue during my recent package upgrade, and not finding any direction on how to downgrade, I decided to try directly altered the two instances of "7.0.8_13" back to "7.0.8_8" in /cf/conf/config.xml file and then immediately reinstall the package under the normal package manager.  This of course still results in the "7.0.8_13" version, but I thought it might find and address additional configuration issues.
The result was that the configuration for the single WAN interface was completely lost and had to be rebuilt from scratch, whilst the firewall with two Suricata WAN interface configurations survived but both interfaces needed to be manually restarted (did not come back online automatically).
After rebuilding the single interface and restarting the two interfaces, both had no issues with opening and displaying the BLOCKS page (without using the patch).
Whilst I have no idea why it worked, i thought it might help some people out there.
]]></description><link>https://forum.netgate.com/topic/200452/suricata-7.0.8_13-crash-on-26.03</link><guid isPermaLink="true">https://forum.netgate.com/topic/200452/suricata-7.0.8_13-crash-on-26.03</guid><dc:creator><![CDATA[jpv9]]></dc:creator><pubDate>Thu, 02 Apr 2026 03:21:29 GMT</pubDate></item><item><title><![CDATA[Is it possible to implement true block offender&#x27;s IP if IPS is in inline mode?]]></title><description><![CDATA[<p dir="auto">Hello, friendly pfSense community :-)</p>
<p dir="auto">We have a /24 real IPs network behind pfSense, Suricata and pfBlockerNG (pfSense 2.8.1, Suricata 7.0.8_5). I'm looking for a way to combine the best features of both Legacy and Inline IPS modes. I.e. how to block offending IP totally for a good measure of time (3-6 hours) totally if the rule was activated and packet dropped? We switched from "Legacy" to "Inline" mode, and immediately our logs were full of single-type messages, along with attempts to brute-force attack SSH ports on our servers. From the same IP address, over 2,000 were reached in just 10 hours. It really messes up the log files. The best thing to do would be to use something like fail2ban in Linux. This would allow you to allow two to five attempts in two minutes, and then a total ban for 6 to 12 hours for the same IP address.</p>
]]></description><link>https://forum.netgate.com/topic/200421/is-it-possible-to-implement-true-block-offender-s-ip-if-ips-is-in-inline-mode</link><guid isPermaLink="true">https://forum.netgate.com/topic/200421/is-it-possible-to-implement-true-block-offender-s-ip-if-ips-is-in-inline-mode</guid><dc:creator><![CDATA[lokapal]]></dc:creator><pubDate>Fri, 27 Mar 2026 12:20:56 GMT</pubDate></item><item><title><![CDATA[Suricata 7.0.8_5 on pfsense 2.8.1 hangs after enabling]]></title><description><![CDATA[<p dir="auto">Wanted to test Suricata with a basic config<br />
Suricata 7.0.8_5 on pfsense 2.8.1 internet and network hangs after enabling, unbound service stops, ISC DHCP Server stops. I have to disable Suricata and reboot to fix it.</p>
<p dir="auto">Cannot seem to find the logs that shows what the issue is.</p>
<p dir="auto"><strong>Services Suricata Global Settings</strong><br />
ETOpen is a free open source set of Suricata rules whose coverage is more limited than ETPro. - Checked<br />
Use a custom URL for ETOpen downloads - Checked<br />
Install Feodo Tracker Botnet C2 IP rules  - Checked<br />
Install ABUSE.ch SSL Blacklist rules  - Checked</p>
<p dir="auto">ETOpen Custom Rule Download URL<br />
https://rules.emergingthreats.net/open/suricata-7.0.8/emerging.rules.tar.gz</p>
<p dir="auto"><strong>Services Suricata LAN - Interface Settings</strong><br />
Interface LAN<br />
Alert and Block Settings - Unchecked (doing IDS-only atm)</p>
<p dir="auto">Services Suricata Interface Settings LAN - Categories</p>
<p dir="auto">ONLY 	Feodo Tracker Botnet C2 IP Rules is checked</p>
<p dir="auto">AMD Ryzen 5 5600G with Radeon Graphics<br />
12 CPUs : 1 package(s) x 6 core(s) x 2 hardware threads<br />
AES-NI CPU Crypto: Yes (active)<br />
QAT Crypto: No<br />
Memory 16GB memory<br />
Ethernet Controller 10-Gigabit X540-AT2</p>
<p dir="auto">Hardware Checksum Offloading - Unchecked<br />
Hardware TCP Segmentation Offloading - Unchecked<br />
Hardware Large Receive Offloading - Unchecked<br />
hn ALTQ support - Checked</p>
<p dir="auto">I did leave it for 10 mins but the network was still down, not sure what i am doing wrong.</p>
]]></description><link>https://forum.netgate.com/topic/200368/suricata-7.0.8_5-on-pfsense-2.8.1-hangs-after-enabling</link><guid isPermaLink="true">https://forum.netgate.com/topic/200368/suricata-7.0.8_5-on-pfsense-2.8.1-hangs-after-enabling</guid><dc:creator><![CDATA[aGeekhere]]></dc:creator><pubDate>Mon, 16 Mar 2026 10:59:28 GMT</pubDate></item><item><title><![CDATA[Snort SID Management Syntax]]></title><description><![CDATA[The physical files themselves (the sample SID Management Configuration files) are installed with the Snort package into /var/db/snort. Then, if it's a first-time green field installation, the contents of those sample files are migrated into the config.xml file of the firewall as Base64 encoded text by the post-installation script and stored there from then on.
If they are not showing for the OP, then somehow they were accidentally deleted is my best guess. The GUI will allow them to be deleted.
]]></description><link>https://forum.netgate.com/topic/200174/snort-sid-management-syntax</link><guid isPermaLink="true">https://forum.netgate.com/topic/200174/snort-sid-management-syntax</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Tue, 17 Feb 2026 11:44:42 GMT</pubDate></item><item><title><![CDATA[Snort 4.1.7_3 - Alerts tab link in GID:SID column goes to a snort.org URL with document missing]]></title><description><![CDATA[@bmeeks: Great advice, thanks again.
]]></description><link>https://forum.netgate.com/topic/200052/snort-4.1.7_3-alerts-tab-link-in-gid-sid-column-goes-to-a-snort.org-url-with-document-missing</link><guid isPermaLink="true">https://forum.netgate.com/topic/200052/snort-4.1.7_3-alerts-tab-link-in-gid-sid-column-goes-to-a-snort.org-url-with-document-missing</guid><dc:creator><![CDATA[Shawesome]]></dc:creator><pubDate>Sat, 31 Jan 2026 18:03:32 GMT</pubDate></item><item><title><![CDATA[Snort Alerts for a connection without FW rule]]></title><description><![CDATA[@elmnts

shouldnt I see the initial connect in the Snort log

Depends on the rule. E.g. packets from a listed IP.
]]></description><link>https://forum.netgate.com/topic/199988/snort-alerts-for-a-connection-without-fw-rule</link><guid isPermaLink="true">https://forum.netgate.com/topic/199988/snort-alerts-for-a-connection-without-fw-rule</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sun, 25 Jan 2026 10:47:10 GMT</pubDate></item><item><title><![CDATA[Looks Like I Broke Snort]]></title><description><![CDATA[It's very simple to test the functionality of Snort.
Install nmap on any laptop or PC on your network. Run a simple SYN scan against the firewall's interface IP for a network that has a Snort instance running on it with the Emerging Threats SCAN rule set enabled.
nmap -sS &lt;target_ip_address&gt;

If the above command generates connection attempt alerts, then Snort on that interface is working. If you see nothing, then Snort is either not actually running or the needed rules are not installed/enabled. Note that you won't get blocks from this test because the firewall interface IPs should all be in the automatic Pass List, but you will see ALERTS from the attempts.
]]></description><link>https://forum.netgate.com/topic/199936/looks-like-i-broke-snort</link><guid isPermaLink="true">https://forum.netgate.com/topic/199936/looks-like-i-broke-snort</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Mon, 19 Jan 2026 17:47:43 GMT</pubDate></item><item><title><![CDATA[configure Suricata with Wazuh]]></title><description><![CDATA[<p dir="auto">hello all!</p>
<p dir="auto">I am attempting to incorporate Wazuh into my network security.  The Wazuh site states</p>
<p dir="auto">"There are several ways to integrate pfSense with Wazuh. The easiest method is syslog, but you can also use the Wazuh agent. Wazuh agent (native package for pfSense) is already pre-installed In pfSense which is available in Yandex Cloud Marketplace/VK Cloud Marketplace. Therefore, you can start setting up immediately, bypassing the installation process."</p>
<p dir="auto">I do not see one.  It then explains how to use by configuring Suricata, and finally, it explains how to  import the syslog itself.  But all reference restarting the "Agent".</p>
<p dir="auto">Several sites show how to 'fix' pfsense to get packages directly from FreeBSD repositories, but that seems to be fairly dangerous.</p>
<p dir="auto">So does anyone have a reference on how to send syslogs from PfSense to Wazuh without "backdoor tinkering"?</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/topic/199387/configure-suricata-with-wazuh</link><guid isPermaLink="true">https://forum.netgate.com/topic/199387/configure-suricata-with-wazuh</guid><dc:creator><![CDATA[detox]]></dc:creator><pubDate>Fri, 21 Nov 2025 14:13:48 GMT</pubDate></item><item><title><![CDATA[So why is Netflix hitting me with Dradis?]]></title><description><![CDATA[@Patch said in So why is Netflix hitting me with Dradis?:

The information they are after on your device is screen fingerprinting (to identify content played not from them). And any thing else they can see on your network.


The overall effect is a rather high price for a country. Clearly an individual can’t change this on their own but neither must an individual accept or support it.

Interested in a source for the claims.
I thought targeted advertising was frighteningly cheap?
]]></description><link>https://forum.netgate.com/topic/199381/so-why-is-netflix-hitting-me-with-dradis</link><guid isPermaLink="true">https://forum.netgate.com/topic/199381/so-why-is-netflix-hitting-me-with-dradis</guid><dc:creator><![CDATA[ssullivan556]]></dc:creator><pubDate>Fri, 21 Nov 2025 07:28:19 GMT</pubDate></item><item><title><![CDATA[Suricata not starting on Netgate 8200]]></title><description><![CDATA[<p dir="auto">Hello team,</p>
<p dir="auto">I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 		7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface.<br />
It leaves no logs in the System logs, it leaves no logs in suricata.log at</p>
<pre><code>/var/log/suricata/suricata_ovpns933787/suricata.log
</code></pre>
<p dir="auto">I tried launching it manually:</p>
<pre><code># /usr/local/bin/suricata -V
</code></pre>
<p dir="auto">or</p>
<pre><code># /usr/local/bin/suricata -c  /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787
</code></pre>
<p dir="auto">and I get this output</p>
<pre><code>ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8"
</code></pre>
<p dir="auto">Thanks in advance,<br />
Dara</p>
]]></description><link>https://forum.netgate.com/topic/199283/suricata-not-starting-on-netgate-8200</link><guid isPermaLink="true">https://forum.netgate.com/topic/199283/suricata-not-starting-on-netgate-8200</guid><dc:creator><![CDATA[DARA]]></dc:creator><pubDate>Sat, 08 Nov 2025 15:46:47 GMT</pubDate></item><item><title><![CDATA[suricata vulnerability CVE-2025-12490]]></title><description><![CDATA[Here. I think.
Referenced as "github.com: vendor-provided URL vendor-advisory" in your link.
]]></description><link>https://forum.netgate.com/topic/199262/suricata-vulnerability-cve-2025-12490</link><guid isPermaLink="true">https://forum.netgate.com/topic/199262/suricata-vulnerability-cve-2025-12490</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Fri, 07 Nov 2025 17:19:35 GMT</pubDate></item><item><title><![CDATA[Suricata ETOpen rules failing to update]]></title><description><![CDATA[@bmeeks
Understood.  Thank for kindly for your help.  I will likely be ordering a new unit soon.
]]></description><link>https://forum.netgate.com/topic/199201/suricata-etopen-rules-failing-to-update</link><guid isPermaLink="true">https://forum.netgate.com/topic/199201/suricata-etopen-rules-failing-to-update</guid><dc:creator><![CDATA[RedDelPaPa]]></dc:creator><pubDate>Sun, 02 Nov 2025 15:26:12 GMT</pubDate></item><item><title><![CDATA[Forwarding Suricata Logs to ELK or Graylog]]></title><description><![CDATA[@Greyhat
I think it's useful to work with what we've got and figure something out for the (i hope) edge cases later.
So for the JSON I figured you can actually use an existing suricata integration by co-opting their pipelines.
]]></description><link>https://forum.netgate.com/topic/199135/forwarding-suricata-logs-to-elk-or-graylog</link><guid isPermaLink="true">https://forum.netgate.com/topic/199135/forwarding-suricata-logs-to-elk-or-graylog</guid><dc:creator><![CDATA[b3rt]]></dc:creator><pubDate>Mon, 27 Oct 2025 10:59:12 GMT</pubDate></item><item><title><![CDATA[Throughput drop on Netgate 8200 MAX LAN&#x2F;VLAN (ix1) with Suricata inline mode]]></title><description><![CDATA[@smsigroupit said in Throughput drop on Netgate 8200 MAX LAN/VLAN (ix1) with Suricata inline mode:

@bmeeks
Thank you for the reply.
Switching Suricata’s Run Mode to Workers resolved the throughput drop. Really appreciate the help!

Ah --- yes. I forgot to mention trying Workers Run Mode in my previous post. Workers mode allows the netmap packet handling module to avoid the need to lock the netmap rings during critical functions.
]]></description><link>https://forum.netgate.com/topic/199033/throughput-drop-on-netgate-8200-max-lan-vlan-ix1-with-suricata-inline-mode</link><guid isPermaLink="true">https://forum.netgate.com/topic/199033/throughput-drop-on-netgate-8200-max-lan-vlan-ix1-with-suricata-inline-mode</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Tue, 14 Oct 2025 01:42:42 GMT</pubDate></item><item><title><![CDATA[Clear NDR. Could pfSense team take a look and may be replace Suricata with this?]]></title><description><![CDATA[@bmeeks There community edition as well, when I'm asked about pfSense package, I mean community edtition. Plus Suricata 8.0 a huge step forward from previous releases.BTW any plan to integrate Suricata 8.0 in pfSense?
https://www.stamus-networks.com/clear-ndr-community.
]]></description><link>https://forum.netgate.com/topic/198972/clear-ndr.-could-pfsense-team-take-a-look-and-may-be-replace-suricata-with-this</link><guid isPermaLink="true">https://forum.netgate.com/topic/198972/clear-ndr.-could-pfsense-team-take-a-look-and-may-be-replace-suricata-with-this</guid><dc:creator><![CDATA[Antibiotic]]></dc:creator><pubDate>Mon, 06 Oct 2025 20:56:31 GMT</pubDate></item><item><title><![CDATA[Suricata 7.0.8_3 IPS Mode Not Blocking on pfSense 2.8.1]]></title><description><![CDATA[@SteveITS Pass lists are completely blank. there are some blocks that have occured so it seems to be blocking some things.
]]></description><link>https://forum.netgate.com/topic/198802/suricata-7.0.8_3-ips-mode-not-blocking-on-pfsense-2.8.1</link><guid isPermaLink="true">https://forum.netgate.com/topic/198802/suricata-7.0.8_3-ips-mode-not-blocking-on-pfsense-2.8.1</guid><dc:creator><![CDATA[kkierii]]></dc:creator><pubDate>Wed, 17 Sep 2025 18:55:53 GMT</pubDate></item><item><title><![CDATA[DPI (Deep Packet Inspection) and pfSense]]></title><description><![CDATA[@SteveITS Thank you for the reply. I understand. Hopefully its picked back up.
]]></description><link>https://forum.netgate.com/topic/198778/dpi-deep-packet-inspection-and-pfsense</link><guid isPermaLink="true">https://forum.netgate.com/topic/198778/dpi-deep-packet-inspection-and-pfsense</guid><dc:creator><![CDATA[beloc]]></dc:creator><pubDate>Mon, 15 Sep 2025 19:54:53 GMT</pubDate></item><item><title><![CDATA[Patch notes for suricata 7.0.8_3?]]></title><description><![CDATA[It was all CVE fixes in the PHP GUI part of the package. See the Redmine ticket here: https://redmine.pfsense.org/issues/16414.
]]></description><link>https://forum.netgate.com/topic/198732/patch-notes-for-suricata-7.0.8_3</link><guid isPermaLink="true">https://forum.netgate.com/topic/198732/patch-notes-for-suricata-7.0.8_3</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Wed, 10 Sep 2025 02:55:42 GMT</pubDate></item><item><title><![CDATA[Snort Alert list explanation]]></title><description><![CDATA[@icoso said in Snort Alert list explanation:

If I only run it on the LAN ports wouldn't that only prevent my users from going outbound to certain IP's?

I think you're misunderstanding how it works.  In legacy mode it will check for "bad" packets going past the router, and add the "bad" IP to a table/alias, and the firewall will block packets to/from that table.  It is not directional in the sense of "it's on LAN so only watches outbound."
Running it on LAN also identifies which internal device triggered the rule because otherwise on WAN it is after NAT, since it's outside the firewall.
You can run it on WAN, sure.  Some do if they have a lot of internal interfaces and don't want that many Snort/Suricata processes running.  It's a tradeoff of "scanning packets that will never actually arrive" vs convenience/RAM usage.
Here is the setting I mentioned in Suricata; the packages are similar to maybe Snort has it also:
[image: 1757427238489-8223c7ca-ba6c-4503-8668-2b7c03e597ef-image.png]
However, on the Snort interface settings click the View List button by "IP Pass List" and you'll see which IPs are ignored by default.
]]></description><link>https://forum.netgate.com/topic/198722/snort-alert-list-explanation</link><guid isPermaLink="true">https://forum.netgate.com/topic/198722/snort-alert-list-explanation</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Mon, 08 Sep 2025 22:32:22 GMT</pubDate></item><item><title><![CDATA[Feodo Tracker Botnet C2 IP Rules down for almost 48h]]></title><description><![CDATA[@Gradius said in Feodo Tracker Botnet C2 IP Rules down for almost 48h:

Any mirror or alternative ?

No - AFAIK ...
Edit (08.09.2025): Its UP again!
]]></description><link>https://forum.netgate.com/topic/198709/feodo-tracker-botnet-c2-ip-rules-down-for-almost-48h</link><guid isPermaLink="true">https://forum.netgate.com/topic/198709/feodo-tracker-botnet-c2-ip-rules-down-for-almost-48h</guid><dc:creator><![CDATA[fireodo]]></dc:creator><pubDate>Sun, 07 Sep 2025 07:30:19 GMT</pubDate></item><item><title><![CDATA[Suricata log mgmt settings ineffective]]></title><description><![CDATA[I have struggled with the log sizes getting too big and then the web pages refusing to list things on them (alerts/blocks pages show empty in UI).
Clearing the logs manually instantly fixes the UI issue.
I think the problem is the fact that logs can grow quite quickly and that relying on the log rotation can lead to a (very minimal) denial of service type event.
I've thought about mucking with how often it rotates but as long as I'm not being legit DDOS'd it is just a nuisance.  Suricata still clearly works.  The firewall itself clearly works.  The only real problem is UI issues when attempting to do a real investigation or troubleshoot.  One can work around that manually.
Of course somebody will simply say turn suricata off on the external interface.  No.  Occasionally good research happens there.
]]></description><link>https://forum.netgate.com/topic/198704/suricata-log-mgmt-settings-ineffective</link><guid isPermaLink="true">https://forum.netgate.com/topic/198704/suricata-log-mgmt-settings-ineffective</guid><dc:creator><![CDATA[skogs]]></dc:creator><pubDate>Sat, 06 Sep 2025 03:36:04 GMT</pubDate></item></channel></rss>