From ArchWiki
Revision as of 00:56, 12 August 2013 by Aatdark (talk | contribs) (created article)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Tango-edit-clear.pngThis article or section needs language, wiki syntax or style improvements.Tango-edit-clear.png

Reason: please use the first argument of the template to provide a brief explanation. (Discuss in Talk:Suricata#)

From the project home page:

Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine. Open Source and owned by a community run non-profit foundation, the Open Information Security Foundation (OISF). Suricata is developed by the OISF and its supporting vendors.


Install suricataAUR from the AUR.


The main configuration file is /etc/suricata/suricata.yaml.

You should change the following parts of the config in order to make it run:

  default-log-dir: /var/log/suricata/     # where you want to store log files
  HOME_NET: "[]"                # your local network
  host-os-policy:   ..                    # according to the OS running the ips