Time to plug my Simple-IDS tool again, IMO the easiest way to try Suricata with a web UI (EveBox) - just provide the interface name: https://evebox.org/simple-ids/ -- Docker or Podman required, but they're ubiquitous now right? #suricata #ids #evebox
Simple-IDS - Suricata & EveBox Simply | EveBox

Simple-IDS is a tool to easily run Suricata and EveBox on Linux systems

@ish i like idea of pkt cap - biz really needs it for audit trail #arkime