# \#community

**URL:** https://forum.suricata.io/tag/community/5.md

[Latest](https://forum.suricata.io/latest.md) · [Categories](https://forum.suricata.io/categories.md) · [Tags](https://forum.suricata.io/tags.md)

---

## [Goodbye, will retire from work](https://forum.suricata.io/t/goodbye-will-retire-from-work/6419)

<div class="topic-metadata">

**Author:** [@atbohmer](https://forum.suricata.io/u/atbohmer)\
**Replies:** 5\
**Last updated:** [August 7, 2026, 8:26am UTC](https://forum.suricata.io/t/goodbye-will-retire-from-work/6419 "2026-08-07T08:26:46Z")

</div>

Hello, July 31 will be my last working day, after that I will retire from work. Thanks for all the years of community support on this great product! All the best, André

---

## [Suricata Dashboard](https://forum.suricata.io/t/suricata-dashboard/6293)

<div class="topic-metadata">

**Author:** [@DZIDULA\_GATI](https://forum.suricata.io/u/DZIDULA_GATI)\
**Replies:** 0\
**Last updated:** [May 14, 2026, 7:27am UTC](https://forum.suricata.io/t/suricata-dashboard/6293 "2026-05-14T07:27:07Z")

</div>

Hello everyone, When it comes to monitoring Suricata alerts, many of us usually rely on integrations that can become resource-intensive and sometimes overly complex to configure. In some environments, you just want some…

---

## [SuriGuard: A Open Source Graphical Interface for Suricata Logs- - Seeking Contributors and Testers](https://forum.suricata.io/t/suriguard-a-open-source-graphical-interface-for-suricata-logs-seeking-contributors-and-testers/5179)

<div class="topic-metadata">

**Author:** [@Aaron\_Madison](https://forum.suricata.io/u/Aaron_Madison)\
**Replies:** 5\
**Last updated:** [May 14, 2026, 7:19am UTC](https://forum.suricata.io/t/suriguard-a-open-source-graphical-interface-for-suricata-logs-seeking-contributors-and-testers/5179 "2026-05-14T07:19:16Z")

</div>

Hello Suricata Community, This project aims to simplify Suricata log processing and make it more accessible to a broader audience, including network analysts, security teams, and even new users unfamiliar with command-l…

---

## [ClearNDR Community Version](https://forum.suricata.io/t/clearndr-community-version/6282)

<div class="topic-metadata">

**Author:** [@AshZolfi](https://forum.suricata.io/u/AshZolfi)\
**Replies:** 2\
**Last updated:** [May 7, 2026, 8:53am UTC](https://forum.suricata.io/t/clearndr-community-version/6282 "2026-05-07T08:53:48Z")

</div>

Hi, I recently started using ClearNDR and need some help with applying filters and creating policies. I find the information overwhelming and have been trying to reduce the amount of data by applying filters, focusing o…

---

## [Showcasing my custom Suricata-powered security firewall project focused on real-time traffic inspection, threat detection, and operational visibility.](https://forum.suricata.io/t/showcasing-my-custom-suricata-powered-security-firewall-project-focused-on-real-time-traffic-inspection-threat-detection-and-operational-visibility/6263)

<div class="topic-metadata">

**Author:** [@Sincan2](https://forum.suricata.io/u/Sincan2)\
**Replies:** 2\
**Last updated:** [May 4, 2026, 3:36pm UTC](https://forum.suricata.io/t/showcasing-my-custom-suricata-powered-security-firewall-project-focused-on-real-time-traffic-inspection-threat-detection-and-operational-visibility/6263 "2026-05-04T15:36:09Z")

</div>

Hi Suricata community, I’d like to share a project I’ve been building: a custom security firewall powered by Suricata. The goal of this project was to go beyond a basic IDS/IPS setup and build something more practical …

---

## [CGTI Lite 646 Suricata rules + cross-platform management tool for OpenClaw/AI agent threat detection (open source)](https://forum.suricata.io/t/cgti-lite-646-suricata-rules-cross-platform-management-tool-for-openclaw-ai-agent-threat-detection-open-source/6255)

<div class="topic-metadata">

**Author:** [@Senturkselim](https://forum.suricata.io/u/Senturkselim)\
**Replies:** 0\
**Last updated:** [March 31, 2026, 6:36pm UTC](https://forum.suricata.io/t/cgti-lite-646-suricata-rules-cross-platform-management-tool-for-openclaw-ai-agent-threat-detection-open-source/6255 "2026-03-31T18:36:20Z")

</div>

Hi everyone, I’ve been building a Suricata based detection and response tool specifically targeting the threats going after the OpenClaw AI agent ecosystem. Since it’s built entirely on Suricata and I’ve spent significa…

---

## [Suricata logging to console when syslog is enabled](https://forum.suricata.io/t/suricata-logging-to-console-when-syslog-is-enabled/5103)

<div class="topic-metadata">

**Author:** [@toontje](https://forum.suricata.io/u/toontje)\
**Replies:** 5\
**Last updated:** [February 20, 2026, 10:55pm UTC](https://forum.suricata.io/t/suricata-logging-to-console-when-syslog-is-enabled/5103 "2026-02-20T22:55:14Z")

</div>

Suricata version 6.0.10 Operating system and/or Linux distribution “Debian GNU/Linux 12 (bookworm)” How you installed Suricata (from packages) Whenever i enable syslog suricata starts logging to the console. Obviously …

---

## [Influencing EU Strategy: A Call to Support Individual FOSS Developers and "Unsexy" Infrastructure](https://forum.suricata.io/t/influencing-eu-strategy-a-call-to-support-individual-foss-developers-and-unsexy-infrastructure/6180)

<div class="topic-metadata">

**Author:** [@Soner\_Tari](https://forum.suricata.io/u/Soner_Tari)\
**Replies:** 0\
**Last updated:** [January 27, 2026, 12:57pm UTC](https://forum.suricata.io/t/influencing-eu-strategy-a-call-to-support-individual-foss-developers-and-unsexy-infrastructure/6180 "2026-01-27T12:57:48Z")

</div>

Hi everyone, The European Commission is currently seeking feedback on its European Open Digital Ecosystem Strategy (Ares(2026)69111). This is a rare and critical opportunity for the open-source community to influence ho…

---

## [IDMEFv2 connector for Suricata](https://forum.suricata.io/t/idmefv2-connector-for-suricata/6174)

<div class="topic-metadata">

**Author:** [@tbugier](https://forum.suricata.io/u/tbugier)\
**Replies:** 0\
**Last updated:** [January 20, 2026, 12:40pm UTC](https://forum.suricata.io/t/idmefv2-connector-for-suricata/6174 "2026-01-20T12:40:08Z")

</div>

Dear all, As part of the testing of the IETF draft IDMEFv2 (Incident Detection Message Exchange Format) standard, a universal security format to exchange alerts between any security tools (Cyber and Physical) and manage…

---

## [Is mempool-cache-size effective in DPDK mode in Suricata?](https://forum.suricata.io/t/is-mempool-cache-size-effective-in-dpdk-mode-in-suricata/6101)

<div class="topic-metadata">

**Author:** [@gongziw](https://forum.suricata.io/u/gongziw)\
**Replies:** 1\
**Last updated:** [November 6, 2025, 11:43am UTC](https://forum.suricata.io/t/is-mempool-cache-size-effective-in-dpdk-mode-in-suricata/6101 "2025-11-06T11:43:15Z")

</div>

Suricata: 8.0.1 DPDK: 24.11.3 DPDK mempool per-lcore local cache uses rte\_lcore\_id() to get the index. This value is set in EAL worker threads, but is invalid in Suricata worker threads. Suricata add log: static TmEc…

---

## [Specification PC/Computer for using Suricata](https://forum.suricata.io/t/specification-pc-computer-for-using-suricata/6069)

<div class="topic-metadata">

**Author:** [@Masesolo](https://forum.suricata.io/u/Masesolo)\
**Replies:** 4\
**Last updated:** [October 23, 2025, 1:24pm UTC](https://forum.suricata.io/t/specification-pc-computer-for-using-suricata/6069 "2025-10-23T13:24:55Z")

</div>

Hi everyone, please help, i want to deploy suricata in my office, i want to know how to choosen specification (Processor, RAM, Disk) PC/server? if in mikrotik i saw 1000 users connection, and there are 200mbps troughpu…

---

## [\[Suricata Webinar\] See Clear NDR Community 1.0 in Action](https://forum.suricata.io/t/suricata-webinar-see-clear-ndr-community-1-0-in-action/5986)

<div class="topic-metadata">

**Author:** [@dmarkdurrett](https://forum.suricata.io/u/dmarkdurrett)\
**Replies:** 1\
**Last updated:** [August 29, 2025, 4:08pm UTC](https://forum.suricata.io/t/suricata-webinar-see-clear-ndr-community-1-0-in-action/5986 "2025-08-29T16:08:05Z")

</div>

Join Stamus Networks for a live introduction to Clear NDR® Community 1.0, the first and only turnkey Suricata-based Network Detection and Response (NDR) that is delivered as open source. Date & Time: Sep 10, 2025 11:00 …

---

## [Suricata 7.0.5 file\_data not matching keyword near end of HTTP response body](https://forum.suricata.io/t/suricata-7-0-5-file-data-not-matching-keyword-near-end-of-http-response-body/5934)

<div class="topic-metadata">

**Author:** [@abhishek\_sharma](https://forum.suricata.io/u/abhishek_sharma)\
**Replies:** 0\
**Last updated:** [August 17, 2025, 12:58pm UTC](https://forum.suricata.io/t/suricata-7-0-5-file-data-not-matching-keyword-near-end-of-http-response-body/5934 "2025-08-17T12:58:21Z")

</div>

Hello, I’m testing Suricata 7.0.5 and trying to block HTTP traffic based on a keyword inside the file body. I created this rule: drop http any any -\> any any (msg:"Block Doyle Hound book based on content match"; file\_d…

---

## [Error to update rules suricata (suricata version =\>8.0.0-dev (2c0d3b83c 2024-12-13)](https://forum.suricata.io/t/error-to-update-rules-suricata-suricata-version-8-0-0-dev-2c0d3b83c-2024-12-13/5517)

<div class="topic-metadata">

**Author:** [@a\_m](https://forum.suricata.io/u/a_m)\
**Replies:** 4\
**Last updated:** [August 9, 2025, 11:32am UTC](https://forum.suricata.io/t/error-to-update-rules-suricata-suricata-version-8-0-0-dev-2c0d3b83c-2024-12-13/5517 "2025-08-09T11:32:45Z")

</div>

hello, i don’t know how if have to write topic in help category or rules category.but i know my problem: alexandre@alexandre-Matebook:~/Documents$ cat ./suricata-update-script.sh #!/bin/bash # Mise à jour des règles …

---

## [Filtering out literal newlines in base64 payload](https://forum.suricata.io/t/filtering-out-literal-newlines-in-base64-payload/5904)

<div class="topic-metadata">

**Author:** [@Nisarg](https://forum.suricata.io/u/Nisarg)\
**Replies:** 4\
**Last updated:** [August 4, 2025, 10:21pm UTC](https://forum.suricata.io/t/filtering-out-literal-newlines-in-base64-payload/5904 "2025-08-04T22:21:02Z")

</div>

I’ve been messing with pcre and the from\_base64 transform. I’m trying to decode from a json response which contains a literal \\n separated base64 block. The issue is if I use mode rfc4648, it will end the string after th…

---

## [Unable to enable additional rulesets, always defaults to Emerging Threats Open](https://forum.suricata.io/t/unable-to-enable-additional-rulesets-always-defaults-to-emerging-threats-open/5835)

<div class="topic-metadata">

**Author:** [@unknown](https://forum.suricata.io/u/unknown)\
**Replies:** 3\
**Last updated:** [July 23, 2025, 7:30pm UTC](https://forum.suricata.io/t/unable-to-enable-additional-rulesets-always-defaults-to-emerging-threats-open/5835 "2025-07-23T19:30:23Z")

</div>

Hello everyone! I am trying to enable an additional ruleset using suricata-update as described in the documentation. For instancse, following the official guide to enable the OISF TrafficID ruleset I am running the foll…

---

## [Does the dpdk.eal-params.lcores use the same cores in worker-cpu-set?](https://forum.suricata.io/t/does-the-dpdk-eal-params-lcores-use-the-same-cores-in-worker-cpu-set/5885)

<div class="topic-metadata">

**Author:** [@dahaili](https://forum.suricata.io/u/dahaili)\
**Replies:** 1\
**Last updated:** [July 20, 2025, 3:19pm UTC](https://forum.suricata.io/t/does-the-dpdk-eal-params-lcores-use-the-same-cores-in-worker-cpu-set/5885 "2025-07-20T15:19:56Z")

</div>

Hi, This is coreset I configure in dpdk: dpdk: eal-params: proc-type: primary l: “32,34,36,38,40,42,44,46,48,50,52,54” And this is worker-cpu-set I configured: - worker-cpu-set: cpu: \[ 29,31,33,35,37,39,41,43,45,…

---

## [Does Suricata have the capability to save every packet or flow to a PCAP file in real time?](https://forum.suricata.io/t/does-suricata-have-the-capability-to-save-every-packet-or-flow-to-a-pcap-file-in-real-time/5787)

<div class="topic-metadata">

**Author:** [@Jasser\_Hach](https://forum.suricata.io/u/Jasser_Hach)\
**Replies:** 2\
**Last updated:** [June 20, 2025, 3:28pm UTC](https://forum.suricata.io/t/does-suricata-have-the-capability-to-save-every-packet-or-flow-to-a-pcap-file-in-real-time/5787 "2025-06-20T15:28:42Z")

</div>

Additionally, can suricata forward this data to an external script for processing?

---

## [Suricata IPS in Inline Mode and Fail2ban Integration](https://forum.suricata.io/t/suricata-ips-in-inline-mode-and-fail2ban-integration/5724)

<div class="topic-metadata">

**Author:** [@Jasser\_Hach](https://forum.suricata.io/u/Jasser_Hach)\
**Replies:** 6\
**Last updated:** [May 29, 2025, 1:49am UTC](https://forum.suricata.io/t/suricata-ips-in-inline-mode-and-fail2ban-integration/5724 "2025-05-29T01:49:08Z")

</div>

I have successfully set up Suricata in IPS inline mode using AF\_Packet (Ubuntu). To test it, I used testmynids.org, and Suricata correctly blocked the response: root@jasser:/home/jasser# curl --max-time 5 http://testmyn…

---

## [Best Tools for Building a Real-Time Network Attack Detection Pipeline with Machine Learning](https://forum.suricata.io/t/best-tools-for-building-a-real-time-network-attack-detection-pipeline-with-machine-learning/5694)

<div class="topic-metadata">

**Author:** [@Jasser\_Hach](https://forum.suricata.io/u/Jasser_Hach)\
**Replies:** 4\
**Last updated:** [May 27, 2025, 7:38am UTC](https://forum.suricata.io/t/best-tools-for-building-a-real-time-network-attack-detection-pipeline-with-machine-learning/5694 "2025-05-27T07:38:03Z")

</div>

Hi everyone, I’m currently working on building a real-time network intrusion detection pipeline using machine learning, and I’d appreciate some guidance on the best tools and practices. So far, I’ve installed Suricata …

---

## [Iptables after forward is enabled](https://forum.suricata.io/t/iptables-after-forward-is-enabled/5203)

<div class="topic-metadata">

**Author:** [@aishi2000](https://forum.suricata.io/u/aishi2000)\
**Replies:** 1\
**Last updated:** [February 9, 2025, 3:41am UTC](https://forum.suricata.io/t/iptables-after-forward-is-enabled/5203 "2025-02-09T03:41:10Z")

</div>

Suricata version 7.08 Centos 7 The error message is as follows： 01/04/2025-00:28:42.507394 \[\] \[1:2210045:2\] SURICATA STREAM Packet with invalid ack \[\] \[Classification: Generic Protocol Command Decode\] \[Priority: 3\] …

---

## [個人のwindows11でsuricataを利用するにあたり](https://forum.suricata.io/t/windows11-suricata/5640)

<div class="topic-metadata">

**Author:** [@machan](https://forum.suricata.io/u/machan)\
**Replies:** 3\
**Last updated:** [April 24, 2025, 12:57pm UTC](https://forum.suricata.io/t/windows11-suricata/5640 "2025-04-24T12:57:38Z")

</div>

Please include the following information with your help request:Windows１１ Suricata version 8.0.0 64bit Operating system and/or Linux distribution windows11 How you installed Suricata (from source, packages, something…

---

## [Suricata6 drops flow](https://forum.suricata.io/t/suricata6-drops-flow/5592)

<div class="topic-metadata">

**Author:** [@kajamuhaiyadeen](https://forum.suricata.io/u/kajamuhaiyadeen)\
**Replies:** 6\
**Last updated:** [April 10, 2025, 2:47pm UTC](https://forum.suricata.io/t/suricata6-drops-flow/5592 "2025-04-10T14:47:32Z")

</div>

Hi Team, In Suricata 6.0.12 I see below flow drop log but unable to troubleshoot the root cause for this drop. Can somebody share the reason/troubleshooting steps for fixing the below flow drop error ? { “timestamp”: …

---

## [Kafka Output Not Working in Suricata 7.0.6](https://forum.suricata.io/t/kafka-output-not-working-in-suricata-7-0-6/5571)

<div class="topic-metadata">

**Author:** [@chirag.deshlehra](https://forum.suricata.io/u/chirag.deshlehra)\
**Replies:** 2\
**Last updated:** [April 1, 2025, 7:35pm UTC](https://forum.suricata.io/t/kafka-output-not-working-in-suricata-7-0-6/5571 "2025-04-01T19:35:01Z")

</div>

Hi Team, I am facing an issue while attempting to stream logs directly from Suricata to Kafka. I am currently using Suricata version 7.0.6, and I have configured Kafka output in the suricata.yaml file as follows: outpu…

---

## [Af-packet keeps trying to find interface eth0. I specified a different one already](https://forum.suricata.io/t/af-packet-keeps-trying-to-find-interface-eth0-i-specified-a-different-one-already/4826)

<div class="topic-metadata">

**Author:** [@Victor1](https://forum.suricata.io/u/Victor1)\
**Replies:** 5\
**Last updated:** [March 19, 2025, 2:07pm UTC](https://forum.suricata.io/t/af-packet-keeps-trying-to-find-interface-eth0-i-specified-a-different-one-already/4826 "2025-03-19T14:07:53Z")

</div>

Hi Everyone, New user here. Following the Setup Guide. Using Fedora 40. Suricata says in its logs: af-packet: eth0: unable to find af-packet config for interface “eth0” or “default”, using default values \[4049 - Suri…

---

## [Can Suricata be used for dissecting IEC 61850 protocol?](https://forum.suricata.io/t/can-suricata-be-used-for-dissecting-iec-61850-protocol/5396)

<div class="topic-metadata">

**Author:** [@Basu](https://forum.suricata.io/u/Basu)\
**Replies:** 1\
**Last updated:** [February 21, 2025, 10:10pm UTC](https://forum.suricata.io/t/can-suricata-be-used-for-dissecting-iec-61850-protocol/5396 "2025-02-21T22:10:33Z")

</div>

Hi, I am seeking help, whether IEC 61850 GOOSE/Sampled values packets be dissected in Suricata?

---

## [Localhost working but not in ethernet](https://forum.suricata.io/t/localhost-working-but-not-in-ethernet/5391)

<div class="topic-metadata">

**Author:** [@kenpachi](https://forum.suricata.io/u/kenpachi)\
**Replies:** 5\
**Last updated:** [February 21, 2025, 4:01pm UTC](https://forum.suricata.io/t/localhost-working-but-not-in-ethernet/5391 "2025-02-21T16:01:47Z")

</div>

I created local rules and sent packets using Scapy. The only problem is when I used lo (localhost) the rules I created were working, but if I ran the enp0s3 (ethernet), the created rules were not found. Do I still need a…

---

## [Dropping Ddos Attacks](https://forum.suricata.io/t/dropping-ddos-attacks/5191)

<div class="topic-metadata">

**Author:** [@deneme\_yanilma](https://forum.suricata.io/u/deneme_yanilma)\
**Replies:** 1\
**Last updated:** [February 12, 2025, 9:40pm UTC](https://forum.suricata.io/t/dropping-ddos-attacks/5191 "2025-02-12T21:40:58Z")

</div>

Hello, My suricata version 7.0.7 , my operation system is Ubuntu 22.04.2 LTS. I have a test environment with the following setup: PC1 is on Network1, PC2 (which has Suricata running) forwards all traffic, and PC3 is o…

---

## [Can we run suricata in IDS mode with NFQ support](https://forum.suricata.io/t/can-we-run-suricata-in-ids-mode-with-nfq-support/5062)

<div class="topic-metadata">

**Author:** [@dinesh](https://forum.suricata.io/u/dinesh)\
**Replies:** 1\
**Last updated:** [February 12, 2025, 9:01pm UTC](https://forum.suricata.io/t/can-we-run-suricata-in-ids-mode-with-nfq-support/5062 "2025-02-12T21:01:17Z")

</div>

Please include the following information with your help request: Suricata version Operating system and/or Linux distribution How you installed Suricata (from source, packages, something else) Hi, Suricata version -…

---

## [How to test models trained on CICIDS2017?](https://forum.suricata.io/t/how-to-test-models-trained-on-cicids2017/5246)

<div class="topic-metadata">

**Author:** [@LAICEROO](https://forum.suricata.io/u/LAICEROO)\
**Replies:** 0\
**Last updated:** [January 17, 2025, 12:31pm UTC](https://forum.suricata.io/t/how-to-test-models-trained-on-cicids2017/5246 "2025-01-17T12:31:16Z")

</div>

\#!/usr/bin/env python # coding: utf-8 # In\[1\]: import numpy as np import pandas as pd import seaborn as sns import matplotlib.pyplot as plt from sklearn.model\_selection import train\_test\_split, cross\_val\_score from sk…

[Next page](https://forum.suricata.io/tag/community/5.md?match_all_tags=true&page=1&tags%5B%5D=community)
