Implementing Suricata for Network Monitoring in a Windows Environment


Is it feasible to deploy Suricata in a Windows environment for a thesis project?The Windows 2012 server has Active Directory, DNS, and DHCP services.

Probably feasible, but AFAICS difficult to get support for, since the majority of people I know use Suricata on non-Windows systems.

If I wanted to use Suricata in a Windows environment I’d provision an additional separate Linux host, install Suricata there and just feed it traffic from the Windows machines (e.g. via port mirroring from the switch the Windows machines are connected to).