---
title: The Other Side of Suricata
description: You may be surprised to learn that Suricata produces not only IDS alerts but also produces logs of protocol transactions, flow records and full packet capture. In fact, even with rules completely disabled, Suricata will capture and log all protocol transactions. In this and subsequent articles we will illustrate these lesser-known capabilities through a real-world example.
image: https://www.stamus-networks.com/hubfs/TheOtherSideOfSuricata.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# The Other Side of Suricata

 by [Peter Manev](https://www.stamus-networks.com/blog/author/peter-manev) | Oct 06, 2021 | [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Network Security Monitoring](https://www.stamus-networks.com/blog/tag/network-security-monitoring), [IDS-IPS](https://www.stamus-networks.com/blog/tag/ids-ips)

![](https://www.stamus-networks.com/hubfs/TheOtherSideOfSuricata.jpg)

You may be surprised to learn that [Suricata](https://suricata.io/) produces not only IDS alerts but also produces logs of protocol transactions, flow records and full packet capture. In fact, even with rules completely disabled, [Suricata](https://suricata.io/) will capture and log all protocol transactions. In this and subsequent articles we will illustrate these lesser-known capabilities through a real-world example.

# Combining IDS Alerts, NSM Events and PCAP

Much has been written recently - by security pundits and vendors - about the value of combining and correlating network protocol and flow logs and security event or alert data. And for good reasons.

Combining these into a single system provides much more complete visibility into the network activity and enables broad-spectrum threat detection based on signatures, threat intelligence feeds as well as AI/ML-based anomaly detection. In addition, the protocol data provides valuable enrichment and context to the security events and can be used to identify and correlate activity associated with a given asset under attack.

# Suricata misconceptions

Unfortunately, many still believe the old misconception that you must combine two or more different network engines to achieve this.

The truth is, [Suricata](https://suricata.io/) natively delivers not just IDS/IPS detection and alerts, but also all the supporting evidence offered by protocol transaction logs, flow records, full packet capture and extracted files. And it does so with a single, high-performance engine (currently proven to perform at 100Gbps) with zero integration required among these functions.

![Suricata-Generated-Events v2 source](https://www.stamus-networks.com/hs-fs/hubfs/Suricata-Generated-Events%20v2%20source.png?width=1200&name=Suricata-Generated-Events%20v2%20source.png)

So in most practical cases, you need only Suricata to generate all five types of network telemetry required for what's now being referred to as "open NDR."

# Using the extended Suricata feature set

Strangely, there are not many [Suricata](https://suricata.io/) implementations that take full advantage of this fact. As we will demonstrate in this series of articles, the [SELKS open source distribution](https://www.stamus-networks.com/scirius-open-source?hsLang=en) was the first turnkey implementation to incorporate all these Suricata capabilities.

As long time [Suricata](https://suricata.io/) experts, our team at Stamus Networks has taken full advantage of this native capability in our commercial [Stamus ND](https://www.stamus-networks.com/stamus-nd?hsLang=en) and [Stamus NDR](https://www.stamus-networks.com/stamus-ndr?hsLang=en) as well as the open source [SELKS](https://www.stamus-networks.com/scirius-open-source?hsLang=en) solutions built on top of the [Suricata](https://suricata.io/) engine.

The good news is, that you can take advantage of all of this capability in your [Suricata](https://suricata.io/) implementation, too.

In future articles, we will use a single packet capture (PCAP) file run through Suricata to illustrate these native capabilities.

# Suricata began life as an IDS/IPS

[Suricata](https://suricata.io/) started as an open source intrusion detection system (IDS) / intrusion prevention system (IPS) twelve years ago in response to the performance limitations of existing open source systems. Thanks to a fanatically-dedicated team and the community’s help - Suricata has continuously evolved to stay relevant.

Earlier IDS/IPS platforms struggled to provide users with protocol transaction records needed as forensic evidence to support an incident investigation. This led many to perceive “IDS is useless because it simply overwhelms me with alerts with no context.”

Committed to overcoming these limitations, the [OISF](https://oisf.net/) and [Suricata community](https://suricata.io/join-our-community/) developed Suricata into a full blown network security monitoring solution. As a result, Suricata is now able to capture protocol transactions and network flow records to provide evidence, enrichment and correlation as a valuable complement to the original security events.

Note: for a detailed chronological review of Suricata history, see the blog post [*Suricata: The First 12 Years of Innovation *](https://www.stamus-networks.com/blog/suricata-the-first-12-years-of-innovation?hsLang=en)written by my colleague, Éric Leblond.

# Suricata Network Events: a Full-Featured NSM

So, you may be surprised to learn that [Suricata](https://oisf.net/) produces not only IDS alert logs but it also captures protocol data - including flow records and transaction logs. In fact, even with rules completely disabled, Suricata will analyze and log all protocol transactions.

Each log record -- be it an alert log or a specific protocol like HTTP, TLS, SMB, KRB5, etc -- has a flow_id record. That flow_id is unique for the whole session/flow. All logs from that flow share the same ID. For example when [Suricata](https://oisf.net/) generates an alert associated with a visit to a specific web page, it also generates HTTP transaction logs for that flow along with the file transactions, user agents, URLs, full HTTP headers and more.

Suricata can operate in the following modes:

- **IDS** - intrusion detection system: with signatures, Lua scripts, or match lists (e.g., domains, JA3, JA3S, TLS SNI, subject, issuers, HTTP user agents, HTTP hosts, URLs, file checksums, to name a few)
- IPS - intrusion prevention system: with signatures, Lua scripts, or match lists (e.g., domains, JA3, JA3S, TLS SNI, subject, issuers, HTTP user agents HTTP hosts, URLs, file checksums, to name a few)
- **NSM** - network security monitoring: protocol transaction and flow record logging
- FPC - full packet capture
- Hybrid mode - any combination of the above

In the next few articles, we will try to shed some light on what [Suricata](https://suricata.io/) can produce using an example provided by reviewing a single malicious PCAP.

Additionally, [learn more about getting more out of Suricata](https://www.stamus-networks.com/simplifying-suricata?hsLang=en).

The second article in the series is entitled, "[Suricata Myth Busting: Alerts and NSM](https://www.stamus-networks.com/blog/suricata-myths-alerts-and-nsm?hsLang=en)." You can read it [here >>](https://www.stamus-networks.com/blog/suricata-myths-alerts-and-nsm?hsLang=en)

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fthe-other-side-of-suricata%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fthe-other-side-of-suricata%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fthe-other-side-of-suricata%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fthe-other-side-of-suricata%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fthe-other-side-of-suricata%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fthe-other-side-of-suricata%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Peter Manev](https://www.stamus-networks.com/hubfs/Stamus_Peter_Square-1.jpg)

#### Peter Manev

 Peter Manev is the co-founder and chief strategy officer (CSO) at Stamus Networks. He is a member of the executive team at Open Network Security Foundation (OISF). Peter has over 20 years of experience in the IT industry, including enterprise-level IT security practice. He is a passionate user, developer, and explorer of innovative open-source security software, and he is responsible for training as well as quality assurance and testing on the development team of Suricata – the open-source threat detection engine. Peter is a regular speaker and educator on open-source security, threat hunting, and network security at conferences and live-fire cyber exercises, such as Crossed Swords, DeepSec, Troopers, DefCon, RSA, Suricon, SharkFest, and others. Peter resides in Gothenburg, Sweden.

[**](https://www.linkedin.com/in/peter-manev-64918336/) [** ](https://twitter.com/pevma)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Stamus Networks: When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/hubfs/SN-Perimeter-Fails-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

### [When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

SentinelOne's "Edge Decay" research names the threat. Here's how network detection and response...

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.