No IDS Logs After Disabling “Monitor Traffic Only” in IPFire 193

Hi everyone,

I’m using IPFire 191 and I only want to collect IDS logs locally — I no longer intend to forward anything to Wazuh.

I have the following rulesets enabled:

Previously, I had the option “Monitor traffic only” enabled, and I was seeing IDS logs. However, after disabling that option, I’m no longer getting any IDS logs at all.

How can I restore IDS log generation without using “Monitor traffic only”? I want to make sure my IPS is actively logging alerts when malicious traffic is detected.

Thanks in advance for your help!

You need to Monitor Enable or it is off.


You do not have to Enable IPS, That is the blocking feature.
You may wish to turn of remote logging if you are not using it now..

So just to clarify —
There’s no way to have the IDS both actively respond to threats (act as an IPS) and generate logs at the same time?

If I enable “Monitor traffic only”, I’ll get logs, but the IDS won’t actually act or block anything — is that correct?

I just want to be sure I’m not misunderstanding how this works.

Thanks!

1 Like

Check the enable box to have it block.
You must have a monitored interface.

1 Like

Yes.
You must enable it at the top
If you want it to block too.