Hi Peter,
To get the bridge working entailed editing the/etc/network/interfaces file as follows:-
auto eth0
iface eth0 inet manual
auto eth1
iface eth1 inet manual
auto br0
iface br0 inet manual
bridge_ports eth0 eth1
bridge_stp off
bridge_waitport 0
bridge_fd 0
Substitute eth0 and eth1 for the corresponding NICs which form the bridge. Next edit the /etc/sysctl.conf file and uncomment the following line:-
# net.ipv4.ip_forward=1
to:-
net.ipv4.ip_forward=1
Save the file and restart the SELKS device. The bridge should be up and running forwarding traffic between the 2 interfaces. The bridge can then be selected as the interface to be monitored. My glitch was trying to get the traffic to forward on the bridge.
My other glitch was dist-upgrading the SELKS device and crashed Suricata completely. I will be reinstalling everything and reading how to update without breaking things. Will be about 2 hours before I can do anything, because of a glorious South African thing called loadshedding.
Darryl
P.S. Sorry for repeating the email. Just wanted to include it to display on the group.