# Latest

**URL:** https://forum.suricata.io/latest.md?page=2

[Latest](https://forum.suricata.io/latest.md) · [Categories](https://forum.suricata.io/categories.md) · [Tags](https://forum.suricata.io/tags.md)

**Page:** 3

---

## [Suricata HOME\_NET configuration not working properly](https://forum.suricata.io/t/suricata-home-net-configuration-not-working-properly/6344)

<div class="topic-metadata">

**Author:** [@smbakhtiar](https://forum.suricata.io/u/smbakhtiar)\
**Replies:** 4\
**Last updated:** [June 4, 2026, 10:57am UTC](https://forum.suricata.io/t/suricata-home-net-configuration-not-working-properly/6344 "2026-06-04T10:57:27Z")

</div>

Hi I install the suricata in Ubuntu and configure the configuration yaml file where is set HOME\_NET to my LAN IP and EXTERNAL\_NET = “any” , is this configuration is correct for all my network traffic monitoring.

---

## [Is there any way to tell from a flow event that a packet came from a GRE tunnel if there is no alert log?](https://forum.suricata.io/t/is-there-any-way-to-tell-from-a-flow-event-that-a-packet-came-from-a-gre-tunnel-if-there-is-no-alert-log/6355)

<div class="topic-metadata">

**Author:** [@trojec](https://forum.suricata.io/u/trojec)\
**Replies:** 3\
**Last updated:** [June 1, 2026, 2:39pm UTC](https://forum.suricata.io/t/is-there-any-way-to-tell-from-a-flow-event-that-a-packet-came-from-a-gre-tunnel-if-there-is-no-alert-log/6355 "2026-06-01T14:39:13Z")

</div>

Hi, I am looking into Suricata EVE logs and trying to understand whether it is possible to determine that a packet/flow originated from a GRE tunnel when there is no corresponding alert event. In my case, alert events …

---

## [Just a few more days before Call for Talks for SuriCon 2026 closes](https://forum.suricata.io/t/just-a-few-more-days-before-call-for-talks-for-suricon-2026-closes/6356)

<div class="topic-metadata">

**Author:** [@jufajardini](https://forum.suricata.io/u/jufajardini)\
**Replies:** 0\
**Last updated:** [May 29, 2026, 6:14pm UTC](https://forum.suricata.io/t/just-a-few-more-days-before-call-for-talks-for-suricon-2026-closes/6356 "2026-05-29T18:14:26Z")

</div>

We’re only a couple of weeks away from closing our Call for Talks for SuriCon 2026 Lisbon! Are you still pondering whether your talk idea is worth submitting or not? We say: give it a try! SuriCon audiences and talks ar…

---

## [Using Zeek with Suricata? Upcoming zeek workshop](https://forum.suricata.io/t/using-zeek-with-suricata-upcoming-zeek-workshop/6352)

<div class="topic-metadata">

**Author:** [@Jeff\_Lucovsky](https://forum.suricata.io/u/Jeff_Lucovsky)\
**Replies:** 0\
**Last updated:** [May 28, 2026, 11:42am UTC](https://forum.suricata.io/t/using-zeek-with-suricata-upcoming-zeek-workshop/6352 "2026-05-28T11:42:58Z")

</div>

Hey folks, sharing this for anyone running Zeek alongside Suricata. The Zeek team is hosting a free 2-day workshop in Berkeley from September 10–11, with talks from community members on how they’re using Zeek. A few of t…

---

## [Improving Rule Management in Suri Oculus](https://forum.suricata.io/t/improving-rule-management-in-suri-oculus/6348)

<div class="topic-metadata">

**Author:** [@fil104](https://forum.suricata.io/u/fil104)\
**Replies:** 0\
**Last updated:** [May 27, 2026, 1:54pm UTC](https://forum.suricata.io/t/improving-rule-management-in-suri-oculus/6348 "2026-05-27T13:54:25Z")

</div>

I am currently redesigning the rule management subsystem in Suri Oculus, a lightweight Suricata management and analysis platform. At the moment, the Rules interface already supports: enable/disable of rules from the w…

---

## [Pcre vs content](https://forum.suricata.io/t/pcre-vs-content/6346)

<div class="topic-metadata">

**Author:** [@user555](https://forum.suricata.io/u/user555)\
**Replies:** 0\
**Last updated:** [May 26, 2026, 9:24pm UTC](https://forum.suricata.io/t/pcre-vs-content/6346 "2026-05-26T21:24:28Z")

</div>

Hello again! Sorry for being a nuisance, but I have another question. The documentation states that regular expressions are executed last, after content matches: https://docs.suricata.io/en/latest/rules/payload-keywords.…

---

## [Fast\_pattern field](https://forum.suricata.io/t/fast-pattern-field/6336)

<div class="topic-metadata">

**Author:** [@user555](https://forum.suricata.io/u/user555)\
**Replies:** 4\
**Last updated:** [May 26, 2026, 8:02pm UTC](https://forum.suricata.io/t/fast-pattern-field/6336 "2026-05-26T20:02:20Z")

</div>

Good afternoon, dear colleagues. Please explain why some signatures do not contain an explicitly specified fast\_pattern field?

---

## [High computational load due to poor choice of fast\_pattern](https://forum.suricata.io/t/high-computational-load-due-to-poor-choice-of-fast-pattern/6342)

<div class="topic-metadata">

**Author:** [@user555](https://forum.suricata.io/u/user555)\
**Replies:** 0\
**Last updated:** [May 23, 2026, 10:22pm UTC](https://forum.suricata.io/t/high-computational-load-due-to-poor-choice-of-fast-pattern/6342 "2026-05-23T22:22:55Z")

</div>

Hello, dear colleagues. While researching suricata rules profiling, I encountered a question that I cannot clarify without your experience and knowledge. Only one rule is loaded. alert tcp any any \<\> any any (flow:esta…

---

## [Alert limit and detection failure in Suricata](https://forum.suricata.io/t/alert-limit-and-detection-failure-in-suricata/6337)

<div class="topic-metadata">

**Author:** [@user555](https://forum.suricata.io/u/user555)\
**Replies:** 0\
**Last updated:** [May 23, 2026, 8:44am UTC](https://forum.suricata.io/t/alert-limit-and-detection-failure-in-suricata/6337 "2026-05-23T08:44:41Z")

</div>

Hello dear colleagues, I am testing rule performance and have encountered several problems. Could you please help me figure out if I am doing something wrong? The essence of the problem: I generated signatures (file s…

---

## [Installing suricata 8.0.5](https://forum.suricata.io/t/installing-suricata-8-0-5/6326)

<div class="topic-metadata">

**Author:** [@lohama3491](https://forum.suricata.io/u/lohama3491)\
**Replies:** 2\
**Last updated:** [May 22, 2026, 4:06pm UTC](https://forum.suricata.io/t/installing-suricata-8-0-5/6326 "2026-05-22T16:06:42Z")

</div>

Suricata version: 8.0.5 Operating system: Oracle Linux 9 and Oracle Linux 10 Installed suricata from official repo. Hi, I am in the process of updating suricata to latest version, 8.0.5 from 8.0.4. I run sudo dnf inst…

---

## [Don't miss out the SuriCon Call for Talks Deadline!](https://forum.suricata.io/t/dont-miss-out-the-suricon-call-for-talks-deadline/6327)

<div class="topic-metadata">

**Author:** [@jufajardini](https://forum.suricata.io/u/jufajardini)\
**Replies:** 0\
**Last updated:** [May 21, 2026, 4:10pm UTC](https://forum.suricata.io/t/dont-miss-out-the-suricon-call-for-talks-deadline/6327 "2026-05-21T16:10:42Z")

</div>

SuriCon attendees go there to meet the team and other Suricata users, integrators, researchers and enthusiasts. And a big aspect of this are the talks that are presented, because they spotlight what the greater community…

---

## [Suricata 7.0.16 and 8.0.5 packages are now available for Ubuntu on Ubuntu PPA (Launchpad)](https://forum.suricata.io/t/suricata-7-0-16-and-8-0-5-packages-are-now-available-for-ubuntu-on-ubuntu-ppa-launchpad/6323)

<div class="topic-metadata">

**Author:** [@pevma](https://forum.suricata.io/u/pevma)\
**Replies:** 0\
**Last updated:** [May 20, 2026, 10:09am UTC](https://forum.suricata.io/t/suricata-7-0-16-and-8-0-5-packages-are-now-available-for-ubuntu-on-ubuntu-ppa-launchpad/6323 "2026-05-20T10:09:46Z")

</div>

More about Suricata 7.0.16 and 8.0.5 features, improvements and release notes : Suricata 7.0.16 and 8.0.5 packages are now available for Ubuntu on Ubuntu PPA (Launchpad). 20.04 Focal 22.04 Jammy 24.04 Noble 64 bit…

---

## [Suricata 8.0.5 and 7.0.16 released!](https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315)

<div class="topic-metadata">

**Author:** [@jufajardini](https://forum.suricata.io/u/jufajardini)\
**Replies:** 0\
**Last updated:** [May 19, 2026, 4:26pm UTC](https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315 "2026-05-19T16:26:03Z")

</div>

We are pleased to announce the releases of Suricata 8.0.5 and 7.0.16. These are security releases, fixing a number of important issues. This is the first release cycle that reflects a change in vulnerability reporting v…

---

## [Path-B r11: bridging Squid ICAP and Suricata AF\_PACKET IPS with a synthetic FlowBus](https://forum.suricata.io/t/path-b-r11-bridging-squid-icap-and-suricata-af-packet-ips-with-a-synthetic-flowbus/6301)

<div class="topic-metadata">

**Author:** [@Cetux](https://forum.suricata.io/u/Cetux)\
**Replies:** 0\
**Last updated:** [May 18, 2026, 8:00am UTC](https://forum.suricata.io/t/path-b-r11-bridging-squid-icap-and-suricata-af-packet-ips-with-a-synthetic-flowbus/6301 "2026-05-18T08:00:22Z")

</div>

Hi everyone, I would like to share a small preproduction lab project I have been working on: Path-B v8.0-beta1-r11. It is not meant to be a production security gateway and it is not a dashboard project. It is an archit…

---

## [Arkime ClearNDR](https://forum.suricata.io/t/arkime-clearndr/6294)

<div class="topic-metadata">

**Author:** [@AshZolfi](https://forum.suricata.io/u/AshZolfi)\
**Replies:** 1\
**Last updated:** [May 17, 2026, 4:04am UTC](https://forum.suricata.io/t/arkime-clearndr/6294 "2026-05-17T04:04:45Z")

</div>

Hi, I’m looking at Arkime and see a particular IP that has been appearing all the time. This is obviously a false positive, and I would like to exclude it from further scanning. I selected all and then added a tag: “ex…

---

## [Introducing Suricatavel: Governance platform for Suricata](https://forum.suricata.io/t/introducing-suricatavel-governance-platform-for-suricata/6257)

<div class="topic-metadata">

**Author:** [@titoshadow](https://forum.suricata.io/u/titoshadow)\
**Replies:** 7\
**Last updated:** [May 17, 2026, 3:57am UTC](https://forum.suricata.io/t/introducing-suricatavel-governance-platform-for-suricata/6257 "2026-05-17T03:57:14Z")

</div>

Hi everyone ! Today I would like to introduce Suricatavel, a tool to manage a distributed fleet of Suricata sensors without “fumbling with cables”, but in a clear, measurable and repeatable operation, which should ease …

---

## [Suricata Dashboard](https://forum.suricata.io/t/suricata-dashboard/6293)

<div class="topic-metadata">

**Author:** [@DZIDULA\_GATI](https://forum.suricata.io/u/DZIDULA_GATI)\
**Replies:** 0\
**Last updated:** [May 14, 2026, 7:27am UTC](https://forum.suricata.io/t/suricata-dashboard/6293 "2026-05-14T07:27:07Z")

</div>

Hello everyone, When it comes to monitoring Suricata alerts, many of us usually rely on integrations that can become resource-intensive and sometimes overly complex to configure. In some environments, you just want some…

---

## [SuriGuard: A Open Source Graphical Interface for Suricata Logs- - Seeking Contributors and Testers](https://forum.suricata.io/t/suriguard-a-open-source-graphical-interface-for-suricata-logs-seeking-contributors-and-testers/5179)

<div class="topic-metadata">

**Author:** [@Aaron\_Madison](https://forum.suricata.io/u/Aaron_Madison)\
**Replies:** 5\
**Last updated:** [May 14, 2026, 7:19am UTC](https://forum.suricata.io/t/suriguard-a-open-source-graphical-interface-for-suricata-logs-seeking-contributors-and-testers/5179 "2026-05-14T07:19:16Z")

</div>

Hello Suricata Community, This project aims to simplify Suricata log processing and make it more accessible to a broader audience, including network analysts, security teams, and even new users unfamiliar with command-l…

---

## [SuriCon 2026 Call for Talks is still open... But not for long!](https://forum.suricata.io/t/suricon-2026-call-for-talks-is-still-open-but-not-for-long/6292)

<div class="topic-metadata">

**Author:** [@jufajardini](https://forum.suricata.io/u/jufajardini)\
**Replies:** 0\
**Last updated:** [May 13, 2026, 1:51pm UTC](https://forum.suricata.io/t/suricon-2026-call-for-talks-is-still-open-but-not-for-long/6292 "2026-05-13T13:51:57Z")

</div>

Calling all Suricata researchers, fans, enthusiasts, integrators, all who’re trying to take Suricata far and beyond, all who are using Suricata daily to secure their networks and learn more about malware: SuriCon 2026 Ca…

---

## [Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata](https://forum.suricata.io/t/engineering-a-zero-trust-kubernetes-siem-bypassing-nat-blindness-with-ebpf-tc-and-suricata/6291)

<div class="topic-metadata">

**Author:** [@Yeslem\_kh](https://forum.suricata.io/u/Yeslem_kh)\
**Replies:** 0\
**Last updated:** [May 13, 2026, 1:27pm UTC](https://forum.suricata.io/t/engineering-a-zero-trust-kubernetes-siem-bypassing-nat-blindness-with-ebpf-tc-and-suricata/6291 "2026-05-13T13:27:41Z")

</div>

Standard Kubernetes network security is fundamentally broken by NAT blindness. When an intrusion alert fires, traditional tools show a physical node IP, leaving you guessing which of the hundreds of ephemeral pods is act…

---

## [Suri Oculus: Suricata Event Visualization and Analysis Using a Redis Pipeline](https://forum.suricata.io/t/suri-oculus-suricata-event-visualization-and-analysis-using-a-redis-pipeline/6290)

<div class="topic-metadata">

**Author:** [@fil104](https://forum.suricata.io/u/fil104)\
**Replies:** 0\
**Last updated:** [May 13, 2026, 11:46am UTC](https://forum.suricata.io/t/suri-oculus-suricata-event-visualization-and-analysis-using-a-redis-pipeline/6290 "2026-05-13T11:46:02Z")

</div>

Development of the Suri Oculus project continues — a platform for visualization, management, and analysis of Suricata events. One of the main areas of development is the Events Viewer — an interface for viewing, filteri…

---

## [Suricata 8.0.4 fails to start with result 'protocol'](https://forum.suricata.io/t/suricata-8-0-4-fails-to-start-with-result-protocol/6278)

<div class="topic-metadata">

**Author:** [@stormcloud119](https://forum.suricata.io/u/stormcloud119)\
**Replies:** 2\
**Last updated:** [May 8, 2026, 8:25pm UTC](https://forum.suricata.io/t/suricata-8-0-4-fails-to-start-with-result-protocol/6278 "2026-05-08T20:25:38Z")

</div>

Hi, Moving from 7.0.10 on Debian Trixie to 8.0.4 installed through backports repo. With a fresh config file, or using existing, I just get this failure trying to start the service: systemd\[1\]: suricata.service: Failed…

---

## [ClearNDR Community Version](https://forum.suricata.io/t/clearndr-community-version/6282)

<div class="topic-metadata">

**Author:** [@AshZolfi](https://forum.suricata.io/u/AshZolfi)\
**Replies:** 2\
**Last updated:** [May 7, 2026, 8:53am UTC](https://forum.suricata.io/t/clearndr-community-version/6282 "2026-05-07T08:53:48Z")

</div>

Hi, I recently started using ClearNDR and need some help with applying filters and creating policies. I find the information overwhelming and have been trying to reduce the amount of data by applying filters, focusing o…

---

## [Ppa:oisf/suricata-stable updated to pull version 8?](https://forum.suricata.io/t/ppa-oisf-suricata-stable-updated-to-pull-version-8/5898)

<div class="topic-metadata">

**Author:** [@Jeff\_Dyke](https://forum.suricata.io/u/Jeff_Dyke)\
**Replies:** 4\
**Last updated:** [May 7, 2026, 6:28am UTC](https://forum.suricata.io/t/ppa-oisf-suricata-stable-updated-to-pull-version-8/5898 "2026-05-07T06:28:40Z")

</div>

I’m installing Suricata on a server using the basic commands, attempting to keep it at 7x sudo apt install software-properties-common sudo add-repository ppa:oisf/suricata-stable sudo apt update sudo apt install -y suri…

---

## [OISF Suricata PPA does not support Ubuntu 24.04 (noble)](https://forum.suricata.io/t/oisf-suricata-ppa-does-not-support-ubuntu-24-04-noble/4787)

<div class="topic-metadata">

**Author:** [@antoninbas](https://forum.suricata.io/u/antoninbas)\
**Replies:** 5\
**Last updated:** [May 7, 2026, 4:26am UTC](https://forum.suricata.io/t/oisf-suricata-ppa-does-not-support-ubuntu-24-04-noble/4787 "2026-05-07T04:26:53Z")

</div>

Following the Ubuntu installation instructions won’t work on the latest LTS Ubuntu release (noble - 24.04). This is because the OISF PPA for Suricata on Launchpad does not support this Ubuntu release. Is there any plan t…

---

## [Easing server burden for rules downloads](https://forum.suricata.io/t/easing-server-burden-for-rules-downloads/6284)

<div class="topic-metadata">

**Author:** [@DigiAngel](https://forum.suricata.io/u/DigiAngel)\
**Replies:** 0\
**Last updated:** [May 5, 2026, 4:53pm UTC](https://forum.suricata.io/t/easing-server-burden-for-rules-downloads/6284 "2026-05-05T16:53:04Z")

</div>

Hey all. So..I have a handful of machines with Suricata on them. Each does a rule update fine, but, I would rather have just one machine download, and then the others download from the primary machine. My thought was …

---

## [NFLOG config example](https://forum.suricata.io/t/nflog-config-example/5086)

<div class="topic-metadata">

**Author:** [@Nick](https://forum.suricata.io/u/Nick)\
**Replies:** 12\
**Last updated:** [May 5, 2026, 3:35pm UTC](https://forum.suricata.io/t/nflog-config-example/5086 "2026-05-05T15:35:56Z")

</div>

Good time of the day, community! Could someone please share Suricata working config example for NFLOG approach? I have the following inputs: Version: 6.0.10 Linux Debian 12 Installed from package. There is no prob…

---

## [Showcasing my custom Suricata-powered security firewall project focused on real-time traffic inspection, threat detection, and operational visibility.](https://forum.suricata.io/t/showcasing-my-custom-suricata-powered-security-firewall-project-focused-on-real-time-traffic-inspection-threat-detection-and-operational-visibility/6263)

<div class="topic-metadata">

**Author:** [@Sincan2](https://forum.suricata.io/u/Sincan2)\
**Replies:** 2\
**Last updated:** [May 4, 2026, 3:36pm UTC](https://forum.suricata.io/t/showcasing-my-custom-suricata-powered-security-firewall-project-focused-on-real-time-traffic-inspection-threat-detection-and-operational-visibility/6263 "2026-05-04T15:36:09Z")

</div>

Hi Suricata community, I’d like to share a project I’ve been building: a custom security firewall powered by Suricata. The goal of this project was to go beyond a basic IDS/IPS setup and build something more practical …

---

## [Capturing runts](https://forum.suricata.io/t/capturing-runts/6280)

<div class="topic-metadata">

**Author:** [@stuartk](https://forum.suricata.io/u/stuartk)\
**Replies:** 0\
**Last updated:** [May 4, 2026, 10:50am UTC](https://forum.suricata.io/t/capturing-runts/6280 "2026-05-04T10:50:07Z")

</div>

Can anyone confirm that the Napatech NT20E3 captures undersized Ethernet frames? (aka runts: \< 64 bytes in length) The product description suggests that it might … The SmartNIC can capture all frames, including erron…

---

## [Hardware Flow Table on Napatech SmartNICs is never used by Suricata](https://forum.suricata.io/t/hardware-flow-table-on-napatech-smartnics-is-never-used-by-suricata/6277)

<div class="topic-metadata">

**Author:** [@maja](https://forum.suricata.io/u/maja)\
**Replies:** 1\
**Last updated:** [April 30, 2026, 12:06pm UTC](https://forum.suricata.io/t/hardware-flow-table-on-napatech-smartnics-is-never-used-by-suricata/6277 "2026-04-30T12:06:57Z")

</div>

When using Suricata (several Versions 7.0.x and 8.0.x, on Debian bookworm and trixie), I never have been able to successfully use the hardware flow table on Napatech NICs (NT200A02). The ultimate goal is to use the hardw…

[Previous page](https://forum.suricata.io/latest.md?page=1)

[Next page](https://forum.suricata.io/latest.md?page=3)
