I am working on setting up suricata for the first time. I am running it on an Ubuntu 18.04 VM hosted in FreeNas. I have an extra (physical) intel NIC attached to the VM, which is plugged into a SPAN port on my Netgear switch, which is set to mirror TX and RX traffic from the LAN port on my USG Pro.
It seems though when I do a tcpdump on that promisc interface, I only see broadcast and ARP type traffic from the network (mdns, etc. No HTTP traffic or otherwise).
Did miss a step? Any pointers on how to troubleshoot?
Thanks again