IPS log is now empty

Hi,

I’m running with IPF CU 202. Since the 3rd of June around 7 o’clock AM, my IPS log viewer is empty.

The daily PDF report received is also empty :

Of course, I tried to reboot but still empty

So what’s wrong, nothing have changed from my side !

BR

First see if IPS running

Status → Services

Hi Phil

Yes it’s working :slight_smile:

BR

Try
grep -E 'suricata.*<Error>' /var/log/messages

What does a normal day look like? A few hits per day, dozens, hundreds? Which rulesets are activated? What does the Throughput Graph look like at Firewall->Intrusion Prevention?

Hi Tim,

a normal day : few hundreds, example the day before 2nd :

I’m using the Emerging Threats and some rules are activated

The Throughput graph looks normal ? :

so very strange…

Hi Phil

Nothing in error :

And yesterday only one alert received instead of few hundreds per day :

Very very strange…

See Logs → System logs → Intrusion Prevention

Is your network experiencing high traffic?
Your internet connection may be down, Check the Network and Net-Traffic Status graphs.

Do you have a dynamic IP from your ISP? Perhaps the lease expired and you got a new public IP that has much less exposure to the outside world.

After some investigation

Log rotation has reverted from daily in CU201 to weekly in CU202
After fixing this bug

Depending on when you upgraded to CU202, this may have an impact starting on the 7th day.

You should check the files in
/var/log/suricata/fast.log*

But it should return to normal after that.

Hi Phil

could be the explanation but I think I have found the root cause using rulesets from Emergingthreats community. For memory :

  • my last IPS logs stopped at 06h59 the 3rd of June
  • ruleset were updated at 07h01 the 3rd of June

So I have a look in my documentation (screenshots made for my own parameters) and I have discovered that ruleset named ciarmy was removed (not unckecked) since this update :

Before :

image

After the ruleset update :

image

ciarmy was removed. So why ?

BR

It’s not necessarily related to your problem.
Unless you were mainly using this list.

But there must be a problem with the site that provides this list.
I just saw this message:

The cinsscore.com site that provides this list seems to have disappeared this morning!

It’s a third party list that Emerging Threats uses.
They previously also had the 3coresec lists but a year or two ago they stopped providing them.

Some of these third party lists just give up completely or they get taken over by someone who pulls the plug on any free lists.

perhaps a temporary site outage

cinsscore.com was being sponsored by Sentinel IPS but it looks like somewhere along the way they took them over.

On the CINSArmy.com page it has the following

How do I access CINS Scores?

Today, CINS Scores are only available to Sentinel customers using the Sentinel’s web interface. This may change as the CINS system continues to evolve. Until then, feel free to download the CINS Army List and add a new layer of security to your networks.

so the IP Block List txt file had stayed available but now the url for the list can’t access anything.

As the ciarmy list has been removed from the Emerging Threats ruleset that makes it look like it is not just a temporary issue with the download lists but a permanent thing.

I will look at removing the list from the IP Block List.

I would say yes, if it was just the IP Block List and Emerging Threats still had the ciarmy ruleset but just not getting updated.

However as ET have removed the ciarmy section from their ruleset that makes it look to me more like a permanent thing.

I am occassionally able to get the cinsscore.com web site but it is not consistent.

It looks like the cinsscore.com web site has been changed over to the cinsarmy.com web site.

That web site looks to have the same content as the previous one.

They also mention that they provide the ip block list but to get access to it you have to sign up with them and get a token to be able to download them.

After registering with us, we’ll provide you with a unique link and simple token to download a tar file of our public CINS Army Threat Intelligence. The tar contains several formats, including STIX, Snort rules, Suricata rules, and a simple text file.

So the list can no longer be provided in the IP Blocklist as each user has to get a unique token to be able to download it.

They also do say

This list is also distributed through Emerging Threats’ (now Proofpoint) rulesets.

but as ET have removed it from their list that no longer looks accurate unless it is available in another Proofpoint list that you have to pay for.

EDIT:
I have searched the ET forum, which includes all updates to their rules but searching for ciarmy found the last entry was from Dec 2025 and not related to the ruleset no longer being available.

In the Emerging Threats tar archive:
https://rules.emergingthreats.net/open/suricata-5.0/emerging.rules.tar.gz

The ciarmy.rules list still exists, but it is empty.

Yes, I see.

Maybe we just have to wait a few days or a week and see if anything changes. If not then likely no longer available.

EDIT:
Can you tell from your logs when that message about error downloading started? I can then look back in the ET rules updates announcements in that time period.

It’s not necessarily related to your problem.
Unless you were mainly using this list .

But there must be a problem with the site that provides this list.
I just saw this message:

The cinsscore.com site that provides this list seems to have disappeared this morning!

EDIT :

It appears that your messages did indeed originate from this list. (ET CINS …)