Comment on Internal network monitoring

<- View Parent
non_burglar@lemmy.world ⁨4⁩ ⁨days⁩ ago

The mirrored traffic will retain their VLAN tags and Suricata can parse these tags.

I’m not sure how far down this path you’ve gone, but suricata will not automatically correlate primitives into actual alerts from different vlans without transforms, which are cpu-intensive for what they do.

You may want to pull your tap/span/mirror from a point where they converge, like internal side of network egress.

source
Sort:hotnewtop