This is needed so that suricata runs as non-root: https://suricata.readthedocs.io/en/suricata-4.1.2/configuration/dropping-privileges.html
After that, please merge this: https://patchwork.ipfire.org/patch/2125/
Done. https://git.ipfire.org/?p=people/stevee/ipfire-2.x.git;a=commit;h=b051eb68b6c12f619b1c3a76009d41ad59550b6b