Skip to content

Suricata

Status

Planned evaluation — not currently deployed.

Suricata is planned as a hands-on intrusion-detection and network-analysis project after traffic visibility and sensor placement have been designed for the UniFi environment.


Evaluation Goals

  • Learn signature-based network detection
  • Understand rule selection and tuning
  • Investigate alerts against packet and log evidence
  • Measure false positives before treating alerts as incidents
  • Document performance and privacy considerations

Before Deployment

  • Define the traffic source and monitoring scope
  • Select a safe sensor location
  • Plan storage and retention
  • Establish an alert-triage workflow
  • Verify that monitoring does not weaken VLAN isolation

This is roadmap work and is intentionally separated from the currently operating services.