I’m looking to create a script that detects new IPS logs and sends an email notification to the administrator. However, I couldn’t find a specific IPS log file. Does such a file exist, and if so, where can I find it?
If there isn’t a dedicated IPS log file, I was considering either web scraping the IPS log page or parsing the /var/log/messages file to achieve this.
I just realized my Suricata IPS was down for 10 days, without showing anything relevant in the system logs. After an update , system logs just became blank. No errors just blank.