Q. What format does Suricata output events into?

A. Suricata uses the standard Unified2 format. We recommend using Barnyard2 to process events. There is also a newer project called Snorby available. 

 

Q. What rulesets does Suricata use?

A. Suricata will load the standard Snort ruleset as is. Suricata has other capabilities above and beyond the standard Snort rulesets such as those available from VRT and Emerging Threats. There will be new rulesets available once the engine is completely stable and we have need to use Suricata's extended features.

 

Q. Will I have to rewrite all of my local rules?

A. Nope. You can continue to use the same local rules and commercial/community rules you've been using with Snort. There will be new features you can take advantage of with Suricata, but the old stuff will still work just as well! 

 

Q. How do I manage Events generated by Suricata?

A. You can use any number of open and commercial products to manage events. A couple we recommend on the open side are BASE and Squil.

 

 

Donate

OISF Events

05-01-2010 - 05-08-2010
Meeting in San Francisco

05-03-2010
RC 1 Release

06-21-2010 - 06-24-2010
FISL-Brazil

07-01-2010
Phase One Final Release

07-20-2010 - 07-24-2010
OSCON

Find us on Twitter

  • OISF had a great week at RSA! Now back to working on Suricata!

    by OISFoundation Saturday, 06 March 2010 07:56

Search