public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* CU198 Testing - first feedback on Suricata alert email sending
@ 2025-09-29 12:52 Adolf Belka
  2025-09-29 12:58 ` Adolf Belka
  0 siblings, 1 reply; 6+ messages in thread
From: Adolf Belka @ 2025-09-29 12:52 UTC (permalink / raw)
  To: IPFire: Development-List

Hi All,

I just ran the update for CU198 Testing on my vm systems.

The update itself went fine without any error messages or hiccups.

I then went to test the IPS emailing of alerts.

I used the same sender and recipient email addresses as I have specified on the Mail Service WUI page.

I set the alert severity to All, Including Informational Alerts.

I then followed the suricata testing process as defined in
https://docs.suricata.io/en/suricata-8.0.1/quickstart.html#alerting
and I ended up with alerts in the IPS-Logs but no email message received.

I checked the System logs for the mail system and there was no message trying to be sent. I ran the test 7 times, so ended up with 7 messages in the IPS-Logs.

I then checked the IPS system Logs and there was no mention of detecting the alerts and trying to send an email.

I ran the command tail -f /var/log/messages so I could see any additional log entries when I triggered the IPS alerts but again nothing was shown when I triggered the alerts, although the messages did end up in the IPS Logs section.

Regards,

Adolf.



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2025-09-29 16:50 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-29 12:52 CU198 Testing - first feedback on Suricata alert email sending Adolf Belka
2025-09-29 12:58 ` Adolf Belka
2025-09-29 15:44   ` Michael Tremer
2025-09-29 16:10     ` Adolf Belka
2025-09-29 16:37       ` Adolf Belka
2025-09-29 16:50         ` Adolf Belka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox