[Oisf-users] suricata IPS and drop.log

Andreas Herz andi at geekosphere.org
Sun Dec 18 22:02:57 UTC 2016


On 16/12/16 at 12:41, Vieri wrote:
> I'm running Suricata in IPS/inline mode and I'm seeing packets that
> should be dropped according to fast.log but aren't according to
> drop.log.

Can you reproduce with a .pcap and in --simulate-ips mode?

-- 
Andreas Herz



More information about the Oisf-users mailing list