---
title: Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode
description: Suricata Language Server 1.1.0 introduces container mode with Docker support, eliminating local Suricata installation requirements for signature development and testing.
image: https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode

 by [Eric Leblond](https://www.stamus-networks.com/blog/author/eric-leblond) | Nov 13, 2025 | [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [ClearNDR](https://www.stamus-networks.com/blog/tag/clearndr), [Clear NDR Community](https://www.stamus-networks.com/blog/tag/clear-ndr-community)

![](https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg)

Writing and validating Suricata signatures shouldn't require wrestling with complex installation procedures before you can even get started. For the past three years, Suricata Language Server has brought IDE-quality features -- syntax checking, auto-completion, and performance hints -- directly into your favorite editor by leveraging Suricata's own analysis engine. But there's been a catch: you needed a working Suricata installation on your system, which could be a significant barrier depending on your operating system and environment.

Today, we're excited to announce [Suricata Language Server 1.1.0](https://github.com/StamusNetworks/suricata-language-server), which introduces container mode—a game-changing feature that lets you skip the local installation entirely if you have Docker available. Named 'Fluctuat nec mergitur' in remembrance of the November 13, 2015 attacks in Paris, this release makes signature development more accessible than ever.  
The initial version of Suricata Language Server was [published around 3 years ago](https://www.stamus-networks.com/blog/suricata-language-server-real-time-rule-syntax-checking-and-auto-completion?hsLang=en) and it has evolved -- from a features perspective -- without changing the overall architecture.

As a Language Server Protocol implementation, it provides in your favorite editor with syntax checking, completion and performance hints when editing Suricata signatures.

And it does so by using Suricata to get real world analysis. Due to the history of the signature syntax that was inherited from Snort and has evolved over more than 10 years, the syntax checking from an external code base would be mostly full of errors.

As a consequence, all versions up to Suricata Language Server 1.0.0 were using the same technique which was to use a locally-installed instance of Suricata to analyse the buffer containing the signatures. This was powerful because even custom versions of Suricata were supported. Unfortunately, installing Suricata on the operating system was something that could be painful.

Suricata Language Server 1.1.0 enhances this significantly by introducing a container mode where the Suricata commands are run inside a container. Currently this only supports Docker containers, but alternative container implementations will be added soon.

The usage is quite simple as for Visual Code and Codium users, they can just check the `container` checkbox.

![vscode-setup](https://www.stamus-networks.com/hs-fs/hubfs/vscode-setup.png?width=1141&height=765&name=vscode-setup.png)

A specific image can be selected via the `--image` flag so a specific version of Suricata can still be selected. Please note that Suricata Language Server will suppose that an entry point compatible with the one used on jasonish/suricata image is available.

For example, to use Suricata 7.0.13, you can use the following Neovim configuration:

```lua  
local suricata_ls_cmd = {'suricata-language-server','--container', '--image=jasonish/suricata:7.0.13'}  
vim.lsp.config('Suricata LS',  
{  
      cmd = suricata_ls_cmd,  
      filetypes = {'suricata', 'hog'};  
      single_file_support = true;  
      settings = {};  
      on_attach = on_attach,  
}  
)  
vim.lsp.enable('Suricata LS')  
```

As the container is pulled dynamically, the initialization of Suricata Language Server can take time. So the server  
will now warn the editor when it is ready. This can be seen below.

![neovim-status](https://www.stamus-networks.com/hs-fs/hubfs/neovim-status.png?width=1887&height=887&name=neovim-status.png)

The displayed neovim configuration uses `lualine` plugin with the `lsp_status` option:

```lua  
require('lualine').setup {  
  options = {  
    theme = 'material',  
    icons_enabled = true,  
    extensions = {'nvim-tree'},  
  };  
  sections = {lualine_a =};  
}  
```

# Summary

Suricata Language Server 1.1.0 represents a significant step forward in making signature development more accessible. By introducing container mode, we've eliminated one of the primary friction points -- local Suricata installation -- while maintaining the powerful real-world analysis capabilities that set this tool apart from syntax-only checkers. Whether you're using Visual Studio Code, Neovim, or another LSP-compatible editor, getting started with accurate Suricata signature validation is now as simple as having Docker installed.

With support for additional container implementations on the roadmap, we're committed to making Suricata signature development smoother and more efficient for security practitioners everywhere. Download version 1.1.0 today and experience the difference container mode makes in your workflow.

To download this latest version, please visit the [SLS GitHub repository here>>](https://github.com/StamusNetworks/suricata-language-server)

[![Go to SLS Project on GitHub](https://no-cache.hubspot.com/cta/default/6344338/29abce3a-ad02-4607-8cb6-60bafdd24d47.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/29abce3a-ad02-4607-8cb6-60bafdd24d47)

And to engage the open source community about this and other Suricata tools developed by Stamus Networks, please join the discussion on [Discord here >>](https://discord.gg/e6GQKGS5HN)

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fsuricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fsuricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fsuricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fsuricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fsuricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fsuricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Eric Leblond](https://www.stamus-networks.com/hubfs/Stamus_Eric_Square-1.jpg)

#### Eric Leblond

 Éric Leblond is the co-founder and chief technology officer (CTO) at Stamus Networks. He sits on the board of directors at Open Network Security Foundation (OISF). Éric has more than 15 years of experience as co-founder and technologist of cybersecurity software companies and is an active member of the security and open-source communities. He has worked on the development of Suricata – the open-source network threat detection engine – since 2009 and is part of the Netfilter Core team, responsible for the Linux kernel's firewall layer. Eric is a respected expert and speaker on all things network security. Éric resides in Escalles, France.

[**](https://www.linkedin.com/in/ericleblond) [** ](https://twitter.com/Regiteric)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.