Project

General

Profile

Actions

Support #3758

closed

Suricata Installation

Added by Punith Raya almost 4 years ago. Updated almost 4 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:
Beginner

Description

Hello Team,

Since i am very beginner to Suricata setup and we are in testing phase, based on the documentation, tried to setup suricata, installed suricata and configured my one of local network IP as(HOME_NET: “[xx.xx.xx.xx/32]”) in etc/suricata/suricata.yaml and restarted the suricata service, but i could see any logs processing in /var/log/suricata/suricata.log.

Kindly let me know any thing iam missing here?
Note -We are doing testing in AWS and local network IP configured one of Instance public IP.

Regards,
PR


Files

suricata.yaml (73.3 KB) suricata.yaml Punith Raya, 06/22/2020 09:54 AM
Actions #1

Updated by Punith Raya almost 4 years ago

Can someone please help this issue?

Actions #2

Updated by Andreas Herz almost 4 years ago

What Distribution are you using? How did you install suricata? How does the configuration file look like? We need more details about your setup to help.

Actions #3

Updated by Punith Raya almost 4 years ago

Hello Andreas Herz,

Sorry for the delay response, was on vacation last week.

Followed installation doc : https://suricata.readthedocs.io/en/latest/install.html.
Attached suricata yaml file, only config i have changed is HOME_NET, rest everything kept as default.

suricata logs : /var/log/suricata/suricata.log
-----------------------------------
22/6/2020 -- 09:53:00 - <Notice> - This is Suricata version 4.1.5 RELEASE
22/6/2020 -- 09:53:04 - <Notice> - all 1 packet processing threads, 4 management threads initialized, engine started.
---------------------------------------

Actions #4

Updated by Andreas Herz almost 4 years ago

You have duplicated HOME_NET variable set, remove the upper one. But the suricata.log itself looks alright, no error message.

How do you start/run suricata, is the interface setting correct?
How do you test it?
And do you see any output in eve.json log?

Actions #5

Updated by Punith Raya almost 4 years ago

Hello Andreas Herz,

How do you start/run suricata, is the interface setting correct? Started suricata service(systemctl start suricata), what is interface setting and where to configure it?
How do you test it? want to test the network traffic of one of our server
And do you see any output in eve.json log? yes below is the one of the output:
---------- {"timestamp":"2020-06-30T03:16:14.000476+0000","flow_id":1761450600273044,"event_type":"flow","src_ip":"172.bb.6.10","src_port":38040,"dest_ip":"169.mm.mm.123","dest_port":123,"proto":"UDP","app_proto":"ntp","flow":{"pkts_toserver":1,"pkts_toclient":1,"bytes_toserver":90,"bytes_toclient":90,"start":"2020-06-30T03:11:13.496788+0000","end":"2020-06-30T03:11:13.497073+0000","age":0,"state":"established","reason":"timeout","alerted":false}} {"timestamp":"2020-06-30T03:16:18.905884+0000","event_type":"stats","stats":{"uptime":667398,"capture":{"kernel_packets":202372,"kernel_drops":0,"errors":0},"decoder":{"pkts":202373,"bytes":56525730,"invalid":0,"ipv4":141681,"ipv6":5738,"ethernet":202373,"raw":0,"null":0,"sll":0,"tcp":51986,"udp":95251,"sctp":0,"icmpv4":0,"icmpv6":182,"ppp":0,"pppoe":0,"gre":0,"vlan":0,"vlan_qinq":0,"vxlan":0,"ieee8021ah":0,"teredo":0,"ipv4_in_ipv6":0,"ipv6_in_ipv6":0,"mpls":0,"avg_pkt_size":279,"max_pkt_size":1514,"erspan":0,"event":{"ipv4":{"pkt_too_small":0,"hlen_too_small":0,"iplen_smaller_than_hlen":0,"trunc_pkt":0,"opt_invalid":0,"opt_invalid_len":0,"opt_malformed":0,"opt_pad_required":0,"opt_eol_required":0,"opt_duplicate":0,"opt_unknown":0,"wrong_ip_version":0,"icmpv6":0,"frag_pkt_too_large":0,"frag_overlap":0,"frag_ignored":0},"icmpv4":{"pkt_too_small":0,"unknown_type":0,"unknown_code":0,"ipv4_trunc_pkt":0,"ipv4_unknown_ver":0},"icmpv6":{"unknown_type":0,"unknown_code":0,"pkt_too_small":0,"ipv6_unknown_version":0,"ip
v6_trunc_pkt":0,"mld_message_with_invalid_hl":0,"unassigned_type":0,"experimentation_type":0},"ipv6":{"pkt_too_small":0,"trunc_pkt":0,"trunc_exthdr":0,"exthdr_dupl_fh":0,"exthdr_useless_fh":0,"exthdr_dupl_rh":0,"exthdr_dupl_hh":0

Actions #6

Updated by Andreas Herz almost 4 years ago

So you see traffic so it looks like it's running as expected as you can see in the eve.json.

THe interface setting is found in the suricata.yaml ideally you go with the af-packet section.

Actions #7

Updated by Punith Raya almost 4 years ago

Thansk Andreas, i got it.
If i have any further queries will raise a new case, please close this ticket.

Actions #8

Updated by Andreas Herz almost 4 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF