Web interface for Suricata

Continuing the discussion from Road to NS 7 RC:

Let’s make this simple howto!

Done!
http://wiki.nethserver.org/doku.php?id=userguide:web_interface_for_suricata

2 Likes

Great work!

Anyone want to test the suricata package? @quality_team

@jackyes @rasi @JOduMonT @Linux4All @fasttech @EddieA @Adam @Adam_S are the right guys for this task!

Will it work off a tap? Or only on traffic that passes through the server?

Great! :clap: :clap: :clap:

In this case, because ELK stack must be installed, can we resume the following topic?

Improve Mail Log Viewer and Query
Improve Mail Log Viewer and Query

( http://www.tipstuff.org/2014/01/Postfix-log-centralize-and-analysis-in-realtime-with-fluentd-elasticsearch-and-kibana.html )

TIA,
Gabriel

BTW great work @Stll0 :kissing_heart:

It works only if the server is the firewall of the network.

1 Like

Software Center says nethserver-snort, my search result for the package is old, where is suricata?

do you have some free time? :slight_smile:

4 Likes

All done!

2 Likes

This might be of interest to users - I release a new version of EveBox last week that can work without an external database. Instead it can use an embedded SQLite database. Provided you have Suricata logging to /var/log/suricata/eve.log, all you need is the EveBox binary and you can do something like ‘evebox server --datastore sqlite --input /var/log/suricata/eve.json’.

Anyways, just FYI as its useful in environments where Elastic Search is not an option.

4 Likes

@jasonish thanks for jumping into the community :slight_smile: Suricata_IDS core developer?