Skip to content

Suricata

You can integrate Suricata with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Suricata product overview

Suricata is a high-performance, open-source network threat detection engine capable of real-time intrusion detection (IDS), inline intrusion prevention (IPS), and network security monitoring (NSM), developed by the community-run Open Information Security Foundation (OISF).

What we ingest

Sophos XDR collects Suricata EVE JSON data via syslog by forwarding Suricata's eve.json output to a Sophos XDR data collector. The following log categories are collected:

  • Intrusion detections: Suricata signature-based alerts.
  • Web activity: HTTP transactions.
  • DNS activity: DNS queries and responses.
  • Encrypted traffic: TLS session events.
  • Network flows1: Connection flow records.

Event and data types

We ingest the following event and data types from Suricata:

  • Intrusion detections: Suricata signature-based alerts, with the signature, category, severity, and source and destination endpoints. Normalized to network intrusion detection telemetry.
  • Web activity: HTTP transactions, including the URL, method, host, and status. Normalized to HTTP telemetry.
  • DNS activity: DNS queries and responses, including the queried domain and answer. Normalized to DNS query telemetry.
  • Encrypted traffic: TLS session detail, including the server name, version, and certificate subject. Normalized to encrypted-traffic telemetry.
  • Network flows1: Connection flow records, including source and destination, ports, and bytes. Normalized to netflow telemetry.

Data provided by this integration

Data provided by Suricata gets normalized to the following schemas:

  • dnsquery
  • encrypt
  • http
  • netflow 1
  • nids

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview