Homelab Part 7: Snort IDS and T-Pot Honeypot Telemetry

In Part 6, Wazuh started collecting Docker and pfSense logs. In this part, I add detection and deception: Snort on pfSense and T-Pot in the HONEYPOT VLAN. The goal is to generate useful security telemetry, not just run tools. Snort alerts need to reach Wazuh, T-Pot attack logs need to be parsed, and I need to understand why dashboards can look empty even when events exist. What I Built Snort: pfSense package, IDS mode Interfaces: WAN and LAN Rules: Community + focused ET Open categories Honeypot: T-Pot in VLAN 50 Telemetry: T-Pot Suricata eve.json -> Wazuh agent Test source: Kali in VLAN 40 ‹ › ...

2026-05-28 · 4 min · plumy