a Cheat Sheet for Suricata Users
This cheat sheet contains tips and tricks to select, filter and get rapid results from Suricata using JQ - the JSON command-line processing tool - by parsing standard Suricata eve.json logs.
The commands covered in this cheat sheet are focused on the network security monitoring (NSM) data and protocol logs such as SMB, Anomaly, HTTP, DNS, TLS, Flow and others.
Download this cheat sheet as a quick reference guide to the JQ commands used to query Suricata NSM data.
![]()
ABOUT STAMUS® NETWORKS
Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.
© 2014-2026 Stamus Networks, Inc. All rights Reserved.