# Choosing the best Suricata version for AI-driven IDS on RPi 5 (16GB RAM)

**URL:** <https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242>\
**Category:** Help\
**Tags:** suricata\
**Created:** [March 24, 2026, 8:32am UTC](https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242 "2026-03-24T08:32:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ch\_Imene21](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ch_imene21/32/3868_2.png) [@Ch\_Imene21](https://forum.suricata.io/u/Ch_Imene21)\
**Post date:** [March 24, 2026, 8:32am UTC](https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242/1 "2026-03-24T08:32:31Z")

</div>

Hello everyone,

I am currently developing a security system based on **Suricata** running on a **Raspberry Pi 5 (16GB RAM)**. The goal is to build an IDS that uses Suricata not only for signature-based detection but also as a high-fidelity data source for a **Machine Learning (AI) model** aimed at detecting **Zero-Day attacks**.

I’m debating between **Suricata 7.0.x (Stable)** and the newer **Suricata 8.x**.

Since I will be feeding the `eve.json` output into a real-time Python-based ML pipeline for anomaly detection, I have a few specific questions for the experts here:

1. **Stability & Log Consistency:** Is Suricata 8 stable enough on **ARM64** for a production-heavy project, or should I stick to 7.0.x to ensure consistent log formats for my AI features?

2. **Performance Bottlenecks:** To handle the AI processing alongside packet inspection, I’m planning to use an **NVMe SSD** and **Vectorscan** (since Hyperscan isn’t natively available for ARM). Are there any other ARM-specific optimizations you recommend for the Pi 5?

3. **Real-time Export:** Are there specific `eve-log` settings (batching, socket-based export) that work best for minimizing latency between Suricata and a Python ML consumer?

Any advice on the architecture or performance tuning for this hybrid (IDS + AI) setup would be greatly appreciated!

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [March 24, 2026, 8:36am UTC](https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242/2 "2026-03-24T08:36:40Z")

</div>

7 is approaching EOL, so new projects should be done on 8. Suricata is tested on ARM64, so I’m not expecting any issues here.

---

<div class="post-metadata">

**Author:** ![Ch\_Imene21](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ch_imene21/32/3868_2.png) [@Ch\_Imene21](https://forum.suricata.io/u/Ch_Imene21)\
**Post date:** [March 24, 2026, 9:39am UTC](https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242/3 "2026-03-24T09:39:57Z")

</div>

Thank you for the advice!

To be honest, I am still in the testing and prototyping phase, and my top priority right now is maximum stability and ease of configuration. I’ve seen many community discussions suggesting that the 7.0.x branch is currently more mature and stable than version 8 for research-heavy projects like this.

Since I am just starting with the AI/ML integration, I want to avoid the ‘Early Adopter’ headaches and focus on getting the data pipeline right.

If I were to consider Suricata 8 for future-proofing, which specific point release would you say is the most ‘production-ready’ right now? And does version 8 offer a significant performance boost specifically for the Raspberry Pi 5’s architecture that makes the extra configuration complexity worth it?

I’m leaning towards starting with 7.0.15 for its proven track record, but I’m open to your thoughts!

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [March 24, 2026, 9:46am UTC](https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242/4 "2026-03-24T09:46:03Z")

</div>

The EOL of Suricata 7 is scheduled for July 2026, so rather soon, see [EOL Policy - Suricata](https://suricata.io/our-story/eol-policy/) which means there will be no more security updates and bugfixes for it. Thus we would highly recommend using Suricata 8 which will be maintained further and is the current stable.

Always stick with the latest point release, as of today it would be 8.0.4 see [Download - Suricata](https://suricata.io/download/)

There is not much complexity added by using Suricata 8. It would be even easier to start with the fresh Suricata 8 config instead of migration from an older one. Suricata 8 is not “Early Adopter” stage.

---

<div class="post-metadata">

**Author:** ![Ch\_Imene21](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ch_imene21/32/3868_2.png) [@Ch\_Imene21](https://forum.suricata.io/u/Ch_Imene21)\
**Post date:** [March 24, 2026, 6:03pm UTC](https://forum.suricata.io/t/choosing-the-best-suricata-version-for-ai-driven-ids-on-rpi-5-16gb-ram/6242/5 "2026-03-24T18:03:32Z")

</div>

Thank you for advicing !
