Just a quick question. What GUI do you prefer for Suricata? I know some services like PFsense, AWS have them built in, but if you want a super clean GUI for Suricata without a load of other tools built in, what do you go for? I saw IDSTowers but what have you found to be the best general tool for administration?
It would be interesting to know what you would like to see in a Suricata administration tool (especially for me )
good to see you on here, IDS Towers! What would be great is a pre-configured AMI or Build on AWS Marketplace for easy testing. I did go through your configuration process, it did seem quite lengthy.
Personally, I’m looking for a very simple interface with the option to configure in and outbound NICs and several fancy networks and rule-reporting dashboards with some log tables.
There are mostly appliances that have some GUI included like SELKS, OPNSense or IPfire for example. It mostly depends on what you want to do besides just running Suricata. Most of them have it included as one part of the whole solution.
You might be fine with setting up the config and just adding something like ELK for the management of the logfiles.