I'm getting a ton of "SURICATA TCP duplicated option" alerts in SQUIL after doing an sudo soup to the new SURICATA upgrade this morning.
I'm going to tune them out, but was wondering if it just means exactly what it says that's a duplicate alert as I do I have two NICS pulling in tap traffic.
Thanks,
I'm not quite sure. You may be able to find more information by posting here (OISF Users mailing list):
https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
Thanks,
Wes
I just disabled the alert I wasn't able to find out anything more.