Snort/Suricata + Traffic monitoring
I'm trying to understand how I would be able to run either Snort or Suricata alongside traffic monitoring in the way of outputting stats to a Grafana dashboard at the same time.
When I enable Snort or Suricata then I'm unable to collect data to send to Grafana, I understand this is the same problem if I want to start running some form of QoS on the same interface.
Is it possible to port mirror inside pFsense or equally possible to port mirror from my network switch?
Has anyone successfully done this before? I've checked and can't see any guide to do this.
@romprod Can't you send everything to a syslog server and grab the data from there?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.