Suricata
Sensor setting (per sensor). Set a value for each sensor that needs a different value. For conventions, abbreviations, and the other sections, see the Administration configuration reference.
Where: Administration → Configuration → Sensor settings → Suricata
Control the Suricata detection engine on the sensor. The section shows the engine on/off switch and the connection settings (endpoint, port, protocol, and TLS) at the top, then the advanced engine settings below. Change the advanced settings only if you understand the effect.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Default-Log-Dir | Advanced setting for this service. Change only if you understand the effect. |
| text | Restart needed |
Classification-File | Advanced setting for this service. Change only if you understand the effect. |
| text | Restart needed |
Reference-Config-File | Advanced setting for this service. Change only if you understand the effect. |
| text | Restart needed |
Default-Rule-Path | Advanced setting for this service. Change only if you understand the effect. |
| text | Restart needed |
Rule-Files | Advanced setting for this service. Change only if you understand the effect. |
| list of string | Restart needed |
Threshold-File | Advanced setting for this service. Change only if you understand the effect. |
| text | Restart needed |
Vars | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
Runmode | Advanced setting for this service. Change only if you understand the effect. |
| text | Restart needed |
Max-Pending-Packets | Advanced setting for this service. Change only if you understand the effect. |
| number; 1 to no maximum | Restart needed |
Default-Packet-Size | Advanced setting for this service. Change only if you understand the effect. |
| number; 68 to no maximum | Restart needed |
Logging | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
Af-Packet | Advanced setting for this service. Change only if you understand the effect. |
| list of SuricataCaptureInterface | Restart needed |
Pf-Ring | Advanced setting for this service. Change only if you understand the effect. | — | list of SuricataCaptureInterface | Restart needed |
Stats | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
App-layer | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
File-extraction | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
Stream | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings; unit: bytes | Restart needed |
Flow | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings; unit: bytes | Restart needed |
Detection-engine | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
Threading | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
Outputs | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. |
| list of groups | Restart needed |
Unix-command | Advanced setting for this service. Change only if you understand the effect. This is a group of settings. See the sub-settings below. | (see the sub-settings) | group of settings | Restart needed |
Suricata: SuricataConfigVariables sub-settings
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Home-Net | Advanced setting for this service. Change only if you understand the effect. |
| list of string | — |
External-Net | Advanced setting for this service. Change only if you understand the effect. |
| list of string | — |
Address-Groups | Advanced setting for this service. Change only if you understand the effect. | (see the sub-settings) | group of settings | — |
Port-Groups | Advanced setting for this service. Change only if you understand the effect. | (see the sub-settings) | group of settings | — |
Suricata: SuricataLoggingConfig sub-settings
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Default Log Level | Advanced setting for this service. Change only if you understand the effect. |
|
| — |
Outputs | Advanced setting for this service. Change only if you understand the effect. |
| list of item | — |
Suricata: SuricataConfigStats sub-settings
Top-level stats: block configuration.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Enabled | Advanced setting for this service. Change only if you understand the effect. | On | on/off | — |
Interval | Advanced setting for this service. Change only if you understand the effect. |
| number | — |
Suricata: SuricataConfigAppLayer sub-settings
Application layer configuration for protocol parsing .. note:: DNS, SMTP, and other protocols are enabled by default in Suricata v8 while OT protocol parsers are off by default and must be explicitly enabled.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Protocols | Advanced setting for this service. Change only if you understand the effect. | (see the sub-settings) | group of settings | — |
Suricata: SuricataConfigFileExtraction sub-settings
Top-level file-extraction: block. Controls whether Suricata extracts files from parsed protocol streams and which hashes/metadata to compute. This is distinct from the file-store output which controls where carved files are written to disk (see :class:SuricataConfigFileStore). Canonical shape:: file-extraction: enabled: yes force-magic: yes force-hash: [md5, sha256].
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Enabled | Advanced setting for this service. Change only if you understand the effect. | On | on/off | — |
Force-Magic | Advanced setting for this service. Change only if you understand the effect. | On | on/off | — |
Force-Hash | Advanced setting for this service. Change only if you understand the effect. |
| list of string | — |
Suricata: SuricataConfigStream sub-settings
Stream reassembly configuration for full protocol parsing.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Memcap | Advanced setting for this service. Change only if you understand the effect. |
| text | — |
Depth | Advanced setting for this service. Change only if you understand the effect. |
| text | — |
Reassembly | Advanced setting for this service. Change only if you understand the effect. | (see the sub-settings) | group of settings | — |
Suricata: SuricataConfigFlow sub-settings
Flow engine configuration for connection tracking.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Memcap | Advanced setting for this service. Change only if you understand the effect. |
| text | — |
Hash-Size | Advanced setting for this service. Change only if you understand the effect. |
| number; 1024 to no maximum | — |
Prealloc | Advanced setting for this service. Change only if you understand the effect. |
| number; 0 to no maximum | — |
Emergency-Recovery | Advanced setting for this service. Change only if you understand the effect. |
| number; 1 to 100 | — |
Suricata: SuricataConfigDetectionEngine sub-settings
Detection engine configuration for rule matching.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Profile | Advanced setting for this service. Change only if you understand the effect. |
| text | — |
Sgh-Mpm-Algo | Advanced setting for this service. Change only if you understand the effect. |
| text | — |
Suricata: SuricataConfigThreading sub-settings
Threading configuration for high traffic environments.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Thread-Init-Timeout | Advanced setting for this service. Change only if you understand the effect. |
| number; 0 to no maximum | — |
Set-Cpu-Affinity | Advanced setting for this service. Change only if you understand the effect. | Off | on/off | — |
Detect-Thread-Ratio | Advanced setting for this service. Change only if you understand the effect. |
| number; 0.1 to 10.0 | — |
Cpu-Affinity | Advanced setting for this service. Change only if you understand the effect. | — | list of object | — |
Suricata: SuricataConfigOutput sub-settings
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Eve-log | Advanced setting for this service. Change only if you understand the effect. | — | group of settings | — |
Stats | Advanced setting for this service. Change only if you understand the effect. | — | group of settings | — |
File-store | Advanced setting for this service. Change only if you understand the effect. | — | group of settings | — |
Suricata: SuricataConfigUnixCommand sub-settings
Unix command socket for runtime control.
Setting | What it does | Default | Allowed values | Notes |
|---|---|---|---|---|
Enabled | Advanced setting for this service. Change only if you understand the effect. | On | on/off | — |
Filename | Advanced setting for this service. Change only if you understand the effect. |
| text | — |
Related: Suricata signatures
Back to the Administration configuration reference.