Suricata
Status
Planned evaluation — not currently deployed.
Suricata is planned as a hands-on intrusion-detection and network-analysis project after traffic visibility and sensor placement have been designed for the UniFi environment.
Evaluation Goals
- Learn signature-based network detection
- Understand rule selection and tuning
- Investigate alerts against packet and log evidence
- Measure false positives before treating alerts as incidents
- Document performance and privacy considerations
Before Deployment
- Define the traffic source and monitoring scope
- Select a safe sensor location
- Plan storage and retention
- Establish an alert-triage workflow
- Verify that monitoring does not weaken VLAN isolation
This is roadmap work and is intentionally separated from the currently operating services.