Support #3758
closedSuricata Installation
Description
Hello Team,
Since i am very beginner to Suricata setup and we are in testing phase, based on the documentation, tried to setup suricata, installed suricata and configured my one of local network IP as(HOME_NET: “[xx.xx.xx.xx/32]”) in etc/suricata/suricata.yaml and restarted the suricata service, but i could see any logs processing in /var/log/suricata/suricata.log.
Kindly let me know any thing iam missing here?
Note -We are doing testing in AWS and local network IP configured one of Instance public IP.
Regards,
PR
Files
Updated by Andreas Herz almost 4 years ago
What Distribution are you using? How did you install suricata? How does the configuration file look like? We need more details about your setup to help.
Updated by Punith Raya almost 4 years ago
- File suricata.yaml suricata.yaml added
Hello Andreas Herz,
Sorry for the delay response, was on vacation last week.
Followed installation doc : https://suricata.readthedocs.io/en/latest/install.html.
Attached suricata yaml file, only config i have changed is HOME_NET, rest everything kept as default.
suricata logs : /var/log/suricata/suricata.log
-----------------------------------
22/6/2020 -- 09:53:00 - <Notice> - This is Suricata version 4.1.5 RELEASE
22/6/2020 -- 09:53:04 - <Notice> - all 1 packet processing threads, 4 management threads initialized, engine started.
---------------------------------------
Updated by Andreas Herz almost 4 years ago
You have duplicated HOME_NET variable set, remove the upper one. But the suricata.log itself looks alright, no error message.
How do you start/run suricata, is the interface setting correct?
How do you test it?
And do you see any output in eve.json log?
Updated by Punith Raya almost 4 years ago
Hello Andreas Herz,
How do you start/run suricata, is the interface setting correct? Started suricata service(systemctl start suricata), what is interface setting and where to configure it?
How do you test it? want to test the network traffic of one of our server
And do you see any output in eve.json log? yes below is the one of the output:
----------
{"timestamp":"2020-06-30T03:16:14.000476+0000","flow_id":1761450600273044,"event_type":"flow","src_ip":"172.bb.6.10","src_port":38040,"dest_ip":"169.mm.mm.123","dest_port":123,"proto":"UDP","app_proto":"ntp","flow":{"pkts_toserver":1,"pkts_toclient":1,"bytes_toserver":90,"bytes_toclient":90,"start":"2020-06-30T03:11:13.496788+0000","end":"2020-06-30T03:11:13.497073+0000","age":0,"state":"established","reason":"timeout","alerted":false}}
{"timestamp":"2020-06-30T03:16:18.905884+0000","event_type":"stats","stats":{"uptime":667398,"capture":{"kernel_packets":202372,"kernel_drops":0,"errors":0},"decoder":{"pkts":202373,"bytes":56525730,"invalid":0,"ipv4":141681,"ipv6":5738,"ethernet":202373,"raw":0,"null":0,"sll":0,"tcp":51986,"udp":95251,"sctp":0,"icmpv4":0,"icmpv6":182,"ppp":0,"pppoe":0,"gre":0,"vlan":0,"vlan_qinq":0,"vxlan":0,"ieee8021ah":0,"teredo":0,"ipv4_in_ipv6":0,"ipv6_in_ipv6":0,"mpls":0,"avg_pkt_size":279,"max_pkt_size":1514,"erspan":0,"event":{"ipv4":{"pkt_too_small":0,"hlen_too_small":0,"iplen_smaller_than_hlen":0,"trunc_pkt":0,"opt_invalid":0,"opt_invalid_len":0,"opt_malformed":0,"opt_pad_required":0,"opt_eol_required":0,"opt_duplicate":0,"opt_unknown":0,"wrong_ip_version":0,"icmpv6":0,"frag_pkt_too_large":0,"frag_overlap":0,"frag_ignored":0},"icmpv4":{"pkt_too_small":0,"unknown_type":0,"unknown_code":0,"ipv4_trunc_pkt":0,"ipv4_unknown_ver":0},"icmpv6":{"unknown_type":0,"unknown_code":0,"pkt_too_small":0,"ipv6_unknown_version":0,"ip
v6_trunc_pkt":0,"mld_message_with_invalid_hl":0,"unassigned_type":0,"experimentation_type":0},"ipv6":{"pkt_too_small":0,"trunc_pkt":0,"trunc_exthdr":0,"exthdr_dupl_fh":0,"exthdr_useless_fh":0,"exthdr_dupl_rh":0,"exthdr_dupl_hh":0
Updated by Andreas Herz almost 4 years ago
So you see traffic so it looks like it's running as expected as you can see in the eve.json.
THe interface setting is found in the suricata.yaml ideally you go with the af-packet section.
Updated by Punith Raya almost 4 years ago
Thansk Andreas, i got it.
If i have any further queries will raise a new case, please close this ticket.