Hello to all Suricata-IDS developers,
First of all, thank you so much for this great forum.
I have a criticism on this site and I request all developers and experts on the site to prepare tutorial articles for the site. Unfortunately, some topics that are very useful do not have proper training on the site. I myself have a problem about starting Suricata in
AF_PACKET IPS mode and although this mode is very useful, I still haven’t received a proper answer to my questions.
Thank you so much.
Thank you for your appreciation and constructive feedback.
I believe our team has attempted to assist, but it appears the challenges faced might not be directly related to Suricata. We are committed to responding to Suricata forum posts and other social channels on a best-effort basis, which means we address issues as promptly as our resources allow.
However, in our effort, we try to foster the community (and it might not always work out I guess?). At the same time, we are grateful for the community we have, that shows us support and contributes to the open-source idea of the project. We can think of tutorials for individual runmodes and look into enhancing our documentation as we know the crucial role of well-written documentation.
Thank you so much.
I agree, but a bunch of things like Suricata-IDS setup training in different modes should already be on the site. I had provided enough information and reports in the questions I asked, but unfortunately I did not receive an answer.
This is a weakness.
We have a very verbose documentation and people from the community are welcome to add more documentation and guidelines.
It also needs to be emphasized that Suricata is an “expert” tool that requires basic or even advanced knowledge of networking, operating systems and related techniques. Teaching all those basics is out of scope and can be found on different places and in literature.
You opened several new topics and you received a lot of replies, follow-up questions and recommendations.
If you need a full guidance for each step, there are paid training offerings or support.
Especially for non-standard environments and setups it will become quite complex and is somehow out of scope of a free service.
Please follow the suggestions you received in the different topics.
Thanks, but you haven’t read my posts completely. I have gone through all the steps and I think many people have the same problem as me. For example, please take a look at https://forum.suricata.io/t/suricata-ids-does-not-work-in-af-packet-ips-mode/