---
title: SELKS 4 RC1
description: SELKS 4 RC1
image: https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-05-11-15-24.png
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# SELKS 4 RC1

 by [Peter Manev](https://www.stamus-networks.com/blog/author/peter-manev) | Jul 11, 2017 | [SELKS](https://www.stamus-networks.com/blog/tag/selks), [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs)

![](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-05-11-15-24.png)

After a very valuable round of testing and feedback from the community  we are pleased to announce the SELKS 4 RC1 availability.

SELKS is both Live and installable Network Security Management ISO based on Debian implementing and focusing on a complete and ready to use Suricata IDS/IPS ecosystem with its own graphic rule manager. Stamus Networks is a proud member of the Open Source community and SELKS is released under GPLv3 license.

This is a the release candidate of a new major branch with an updated storage visualization stack and latest Suricata.

#### New Features

- [Suricata IDS/IPS/NSM 4.0.x](https://suricata-ids.org/2017/06/28/suricata-4-0-0-rc1-ready-for-testing/) - latest git master Suricata packaged with [Hyperscan enabled](https://01.org/hyperscan) for extra performance boost. This edition of Suricata besides many improvements and bug fixes also includes extra alert data like for example http body added to the alert json logs wherever available.
- [Elasticsearch 5.5.0](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/release-notes-5.5.0.html)  - part of the ELK5 stack upgrade making available a ton of new features and enhancements.
- [Logstash 5.5.0](https://www.elastic.co/guide/en/logstash/5.5/logstash-5-5-0.html) - performance improvement over 2.x and ES5 compatibility.
- [Kibana 5.5.0](https://www.elastic.co/guide/en/kibana/current/release-notes-5.5.0.html) - taking advantage of the latest dashboarding features of ES.
- [Scirius 1.2.2](https://www.stamus-networks.com/2017/03/02/scirius-ce-1-2-0-is-for-ips-and-collaboration/?hsLang=en) - bugfixes, better correlation capability with EveBox and introduction of IPS rules support.
- [Evebox](https://evebox.org/) - many new features including reporting and comments on the log events.
- [Debian Stretch](https://www.debian.org/releases/stretch/) - All new features, kernel and tools.

[![EveBox](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-07-13-53-30-300x158.png?width=300&height=158&name=Screenshot-from-2017-07-07-13-53-30-300x158.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-07-13-53-30.png?hsLang=en)

Alert event with a comment field.

[![Kibana](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-05-11-16-21-300x77.png?width=300&height=77&name=Screenshot-from-2017-07-05-11-16-21-300x77.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-05-11-16-21.png?hsLang=en) Verbose HTTP logging

[![Kibana](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-05-11-15-24-300x112.png?width=300&height=112&name=Screenshot-from-2017-07-05-11-15-24-300x112.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-05-11-15-24.png?hsLang=en) GeoIP heat maps

[![EveBox](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-07-13-52-43-300x160.png?width=300&height=160&name=Screenshot-from-2017-07-07-13-52-43-300x160.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-07-07-13-52-43.png?hsLang=en) Supplemental alert data logging

 

#### Download

To download SELKS4-RC1:

- [Download SELKS4.0RC1](https://www.stamus-networks.com/open-source/?hsLang=en#selks)

#### Usage

Usage and logon credentials (OS and web management user)

- user: `selks-user`
- password: `selks-user` (password in Live mode is `live`)

The default root password is `StamusNetworks`

To remotely access the web management interface :

- [https://your.selks.IP.here/](https://your.selks.IP.here/) - Scirius ruleset management and a central point for all dashboards and EveBox alert and event management.

#### Howto

##### Upgrade

To upgrade your existing SELKS 3 to SELKS 4 preview, please refer to [SELKS-3.0-to-SELKS-4.0-upgrades wiki page](https://github.com/StamusNetworks/SELKS/wiki/SELKS-3.0-to-SELKS-4.0-upgrades---testing).

It is recommended to follow the onscreen instructions and if needed answer "yes" to all changes. At the end of the upgrade you will be asked to enter the interface that you will use for IDS/sniffing. Please enter (eth0 for example) the interface name and reboot when the script is done.

##### Create your own ISO

To create your own SELKS 4 preview ISO (if your host OS is Jessie):

> git clone [https://github.com/StamusNetworks/SELKS.git](https://github.com/StamusNetworks/SELKS.git)  
>  git checkout SELKS4-dev  
>  ./install-deps.sh  
>  cd /usr/share/live/build/data/debian-cd/ && ln -s squeeze stretch  
>  ./build-debian-live.sh

It will take probably 30-40 min and you should end up with the SELKS.iso under the Stamus-Live-Build folder.

##### Once installed/upgraded

- Please feel free to choose the IDS sniffing/listening interface either via the desktop icon Setup-IDS-Interface or via the cmd calling /opt/selks/Scripts/Setup/setup-selks-ids-interface.sh
- Any further upgrades are done via a wrapper script located in /opt/selks/Scripts/Setup/selks-upgrade_stamus.sh
- Recommended set up for SELKS 4.0RC1 is 2CPUs 5-6Gb RAM
- If you need to reset/reload all the dashboards  - you can do like so 
    - In Scirius on the top left corner drop down menu select *System Settings*
    - click on the* Kibana *tab
    - choose *Reset SN dashboards*

#### Feedback is welcome

Give us feedback and get help on:

- Freenode IRC on the #SELKS channel
- [Google Mailing list](http://groups.google.com/d/forum/selks)

While this test upgrade/installation has been verified and tested and aims at upgrading your current SELKS 3.0 to  SELKS 4.0RC1 please make sure you try it in your test/QA set up first and give us any feedback.

Thank you!

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F07%2F11%2Fselks-4-rc1%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F07%2F11%2Fselks-4-rc1%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F07%2F11%2Fselks-4-rc1%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F07%2F11%2Fselks-4-rc1%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F07%2F11%2Fselks-4-rc1%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F07%2F11%2Fselks-4-rc1%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Peter Manev](https://www.stamus-networks.com/hubfs/Stamus_Peter_Square-1.jpg)

#### Peter Manev

 Peter Manev is the co-founder and chief strategy officer (CSO) at Stamus Networks. He is a member of the executive team at Open Network Security Foundation (OISF). Peter has over 20 years of experience in the IT industry, including enterprise-level IT security practice. He is a passionate user, developer, and explorer of innovative open-source security software, and he is responsible for training as well as quality assurance and testing on the development team of Suricata – the open-source threat detection engine. Peter is a regular speaker and educator on open-source security, threat hunting, and network security at conferences and live-fire cyber exercises, such as Crossed Swords, DeepSec, Troopers, DefCon, RSA, Suricon, SharkFest, and others. Peter resides in Gothenburg, Sweden.

[**](https://www.linkedin.com/in/peter-manev-64918336/) [** ](https://twitter.com/pevma)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![](https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

### [Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

Writing and validating Suricata signatures shouldn't require wrestling with complex installation...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.