---
title: SELKS 4.0
description: SELKS 4.0
image: https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-alerts-by-useragent-3.png
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# SELKS 4.0

 by [Peter Manev](https://www.stamus-networks.com/blog/author/peter-manev) | Aug 22, 2017 | [SELKS](https://www.stamus-networks.com/blog/tag/selks), [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs)

![](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-alerts-by-useragent-3.png)

This first edition of SELKS 4 is available from Stamus Networks thanks to a great and helpful feedback from our open source community - Thank you! This new major release features a version jump for all the main software stacks. Suricata switches from 3.2 to 4.0, Elastic stack is ugpraded from 2.5 to 5.5 and even Debian is now Stretch, the latest stable release.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2017-08-22-09-57-20-300x225.png?width=300&height=225&name=Screenshot-from-2017-08-22-09-57-20-300x225.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2017-08-22-09-57-20.png?hsLang=en)

SELKS is both Live and installable Network Security Management ISO based on Debian implementing and focusing on a complete and ready to use Suricata IDS/IPS ecosystem with its own graphic rule manager. Stamus Networks is a proud member of the Open Source community and SELKS is released under GPLv3 license.

This is a major new release featuring all components upgrade and of course latest Suricata.

#### New Features

- [Suricata IDS/IPS/NSM 4.0.x](https://suricata-ids.org/2017/07/27/suricata-4-0-released/) - latest Suricata packaged with [Hyperscan enabled](https://01.org/hyperscan) for extra performance boost. The latest edition of Suricata among many fixes and improvements includes: 
    - extra alert data like for example http body added to the alert json logs wherever available
    - protocol renegociation which means STARTTLS and CONNECT support
- Major upgrade from Elasticsearch/Kibana/Logtsash (ELK) 2.x to the ELK 5 stack making available a ton of new features and enhancements. 
    - [Elasticsearch 5.5.2](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/release-notes-5.5.2.html)
    - [Logstash 5.5.2](https://www.elastic.co/guide/en/logstash/5.5/logstash-5-5-2.html)
    - [Kibana 5.5.2](https://www.elastic.co/guide/en/kibana/current/release-notes-5.5.2.html)
- [Scirius 1.2.4](https://www.stamus-networks.com/2017/03/02/scirius-ce-1-2-0-is-for-ips-and-collaboration/?hsLang=en) - bugfixes, better correlation capability with EveBox and introduction of IPS rules support.
- [Evebox](https://evebox.org/) - many new features including reporting and comments on the log events.
- [Debian Stretch](https://www.debian.org/releases/stretch/) - All new OS features, kernel and tools.

As always - as a Stamus Networks extra sauce the [latest stable kernel (4.12.8 at the time of this writing) is available for install](https://github.com/StamusNetworks/SELKS/wiki/How-to-upgrade-kernel) if you wish.

#### Download

To download SELKS 4:

- SELKS with desktop: [Torrent](http://dl.stamus-networks.com/selks/SELKS-4.0-desktop.iso.torrent), [HTTP](http://dl.stamus-networks.com/selks/SELKS-4.0-desktop.iso) (MD5sum: 70783e4d441932103c3410c0b778b401)
- SELKS without desktop: [Torrent](http://dl.stamus-networks.com/selks/SELKS-4.0-nodesktop.iso.torrent), [HTTP](http://dl.stamus-networks.com/selks/SELKS-4.0-nodesktop.iso) (MD5sum: 335e31cd2b3a864f432c7d57efe007cd)

#### Usage

To remotely access the web management interface :

- [https://your.selks.IP.here/](https://your.selks.IP.here/) - Scirius ruleset management and a central point for all dashboards and EveBox alert and event management.

Usage and logon credentials (OS and web management user)

- user: `selks-user`
- password: `selks-user` (password in Live mode is `live`)

The default root password is `StamusNetworks`

#### Visual tour

Some visuals to give you a glimpse of the things you can do with SELKS.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Scirius-Home-300x147.png?width=300&height=147&name=Scirius-Home-300x147.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Scirius-Home.png?hsLang=en) Scirius - ruleset manager and dashboard central management console.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Scirius-rule-status-300x141.png?width=300&height=141&name=Scirius-rule-status-300x141.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Scirius-rule-status.png?hsLang=en) Scirius - rule availability by ruleset information.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Scirius-rule-search-300x94.png?width=300&height=94&name=Scirius-rule-search-300x94.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Scirius-rule-search.png?hsLang=en) Scirius- "google" search your rules

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-smtp-300x73.png?width=300&height=73&name=Kibana-smtp-300x73.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-smtp.png?hsLang=en) Dashboards - mail attachments

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-top-mail-applications-300x161.png?width=300&height=161&name=Kibana-top-mail-applications-300x161.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-top-mail-applications.png?hsLang=en) Dashboards - mail application supplemental info

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-dns-geoip-heatmap-300x99.png?width=300&height=99&name=Kibana-dns-geoip-heatmap-300x99.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-dns-geoip-heatmap.png?hsLang=en) Dashboards - DNS geoip heat map

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/VLANs-300x149.png?width=300&height=149&name=VLANs-300x149.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/VLANs.png?hsLang=en) Dashboards - VLAN supplemental info

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-events-correlation-300x144.png?width=300&height=144&name=Kibana-events-correlation-300x144.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-events-correlation.png?hsLang=en) Dashboards - availability of full events correlation via EveBox and Scirius

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-http-extra-data-300x138.png?width=300&height=138&name=Kibana-http-extra-data-300x138.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-http-extra-data.png?hsLang=en) Dashboards - extra http data for better visibility.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-ssh-300x149.png?width=300&height=149&name=Kibana-ssh-300x149.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-ssh.png?hsLang=en) Dashboards - ssh data available for drill/break downs as well.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-dns-events-300x150.png?width=300&height=150&name=Kibana-dns-events-300x150.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-dns-events.png?hsLang=en) Dashboards - dns events at a glance

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-alert-suppl-data-300x78.png?width=300&height=78&name=Kibana-alert-suppl-data-300x78.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-alert-suppl-data.png?hsLang=en) Dashboards - alert supplemental log information.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/EveBox-tls-breakdown-300x146.png?width=300&height=146&name=EveBox-tls-breakdown-300x146.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/EveBox-tls-breakdown.png?hsLang=en) EveBox reporting

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-alert-breakdown-300x81.png?width=300&height=81&name=Kibana-alert-breakdown-300x81.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-alert-breakdown.png?hsLang=en) Dashboards - valuable break down of alert data information.

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Kibana-alerts-by-useragent-3-300x113.png?width=300&height=113&name=Kibana-alerts-by-useragent-3-300x113.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Kibana-alerts-by-useragent-3.png?hsLang=en) Dashboards - break down of http user agents that have generated alerts

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/EveBox-alert-comments-300x160.png?width=300&height=160&name=EveBox-alert-comments-300x160.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/EveBox-alert-comments.png?hsLang=en) EveBox - alert comments availability.

 

 

#### Howto

##### Upgrade from SELKS 3

To upgrade your existing SELKS 3 to SELKS 4 preview, please refer to [SELKS-3.0-to-SELKS-4.0-upgrades wiki page](https://github.com/StamusNetworks/SELKS/wiki/SELKS-3.0-to-SELKS-4.0-upgrades).

##### Create your own ISO

SELKS 4 is available for download ready to use (as explained at the beginning of the article).

However - if you want to you can create and/or customize your own SELKS 4 ISO

- [Build a SELKS ISO](https://github.com/StamusNetworks/SELKS/wiki/Building-SELKS)
- [Customizing SELKS](https://github.com/StamusNetworks/SELKS/wiki/Customizing-SELKS)

##### Once installed

- Please refer to [Initial Setup section of the documentation](https://github.com/StamusNetworks/SELKS/wiki#initial-setup)
- [Keep your SELKS up to date](https://github.com/StamusNetworks/SELKS/wiki/SELKS-upgrades)
- Recommended initial set up for SELKS 4.0 is 2CPUs 5-6Gb RAM
- If you need to reset/reload all the dashboards  - you can do like so 
    - In Scirius on the top left corner drop down menu select *System Settings*
    - click on the* Kibana *tab
    - choose *Reset SN dashboards*

#### Feedback is welcome

Any feedback as always is greatly appreciated! :)

Give us feedback and get help on:

- Freenode IRC on the #SELKS channel
- [Google Mailing list](http://groups.google.com/d/forum/selks)

Thank you!

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F08%2F22%2Fselks-4-0%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F08%2F22%2Fselks-4-0%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F08%2F22%2Fselks-4-0%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F08%2F22%2Fselks-4-0%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F08%2F22%2Fselks-4-0%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2017%2F08%2F22%2Fselks-4-0%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Peter Manev](https://www.stamus-networks.com/hubfs/Stamus_Peter_Square-1.jpg)

#### Peter Manev

 Peter Manev is the co-founder and chief strategy officer (CSO) at Stamus Networks. He is a member of the executive team at Open Network Security Foundation (OISF). Peter has over 20 years of experience in the IT industry, including enterprise-level IT security practice. He is a passionate user, developer, and explorer of innovative open-source security software, and he is responsible for training as well as quality assurance and testing on the development team of Suricata – the open-source threat detection engine. Peter is a regular speaker and educator on open-source security, threat hunting, and network security at conferences and live-fire cyber exercises, such as Crossed Swords, DeepSec, Troopers, DefCon, RSA, Suricon, SharkFest, and others. Peter resides in Gothenburg, Sweden.

[**](https://www.linkedin.com/in/peter-manev-64918336/) [** ](https://twitter.com/pevma)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![](https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

### [Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

Writing and validating Suricata signatures shouldn't require wrestling with complex installation...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.