Suricata is a free and open source, mature, fast and robust network threat detection engine.
The Suricata engine is capable of real time intrusion detection (IDS), inline intrusion prevention (IPS), network security monitoring (NSM) and offline pcap processing.
Suricata allows users of DetectionLab to test and develop IDS signatures, as well as being used for PCAP analysis.
/etc/suricata/suricata.yml
suricata-update
The following commands should generate alerts if run from the logger host:
curl -A Blacksun http://example.com
curl http://testmyids.com
index=suricata