Listing Thumbnail

    Suricata 8 IDS/IPS on Ubuntu (Monthly Subscription) by AdvanceCo

     Info
    Deployed on AWS
    AWS Free Tier
    Suricata 8 network intrusion detection and prevention on a hardened, fully patched Ubuntu 24.04 LTS AMI. Inspect traffic from Amazon VPC Traffic Mirroring or inline, send EVE JSON events to your SIEM, and manage rules with suricata-update. Maintained by AdvanceCo with US-based email support.

    Overview

    Suricata is the open-source network threat detection engine developed by the Open Information Security Foundation (OISF). This AMI from AdvanceCo packages Suricata 8 on Ubuntu 24.04 LTS so you can start inspecting AWS network traffic without building and maintaining the sensor yourself.

    What is included

    • Suricata 8.0.x from the official OISF package repository, pinned to the 8.0 release series
    • Ubuntu 24.04 LTS with all available security updates applied when the image is built
    • suricata-update for downloading and refreshing rule sets such as ET Open
    • A systemd service unit for running Suricata as a service
    • A hardened image: root password locked, and no SSH keys, shell history or cloud-init state carried over from the build

    How you can use it

    • Passive IDS with Amazon VPC Traffic Mirroring: Suricata decodes VXLAN-encapsulated mirror traffic, so one sensor can inspect traffic from other instances without changing them.
    • Inline IPS: run Suricata in AF-PACKET inline mode on an instance that routes traffic, and drop traffic that matches your rules.
    • Network security monitoring: EVE JSON logs record alerts plus protocol metadata for HTTP, DNS, TLS, QUIC, SMB, SSH and more, ready to ship to Amazon CloudWatch Logs, Amazon OpenSearch Service or a third-party SIEM.
    • Compliance evidence: network intrusion detection is a common control in frameworks such as PCI DSS, and Suricata's logs can support the evidence you provide for it.

    What Suricata 8 brings

    • A multi-threaded engine that scales with instance vCPUs
    • TLS and QUIC handshake visibility, including SNI and JA3/JA4 fingerprints, without decrypting traffic
    • New and expanded protocol parsers, including LDAP

    Maintenance and support AdvanceCo rebuilds this AMI with current Ubuntu security patches and the latest Suricata 8.0 point release, and publishes updates as new versions of this listing. Included support is by email during US business hours from our US-based team. Paid support with Slack, phone and response-time commitments is available on request.

    Getting started Launch the AMI and connect over SSH as the ubuntu user. Set your capture interface in /etc/suricata/suricata.yaml, run suricata-update to load rules, then restart the suricata service. For Traffic Mirroring, allow UDP 4789 from your mirror sources in the instance security group.

    Highlights

    • Suricata 8 on Ubuntu 24.04 LTS: OISF packages pinned to the 8.0 series, with all Ubuntu security updates applied and the image hardened before release.
    • Built for AWS traffic inspection: VXLAN decoding lets one sensor inspect traffic from Amazon VPC Traffic Mirroring, or run it inline in AF-PACKET IPS mode.
    • SIEM-ready EVE JSON logging: alerts and protocol metadata for HTTP, DNS, TLS, QUIC, SMB and more, with US-based support from AdvanceCo.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Suricata 8 IDS/IPS on Ubuntu (Monthly Subscription) by AdvanceCo

     Info
    Pricing is based on a fixed subscription cost. You pay the same amount each billing period for unlimited usage of the product. Pricing is prorated, so you're only charged for the number of days you've been subscribed. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Fixed subscription cost

     Info
    Monthly subscription
    $625.00/month

    Vendor refund policy

    We do not currently support refunds, but you can cancel at any time.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Suricata 8.0.7 from the OISF 8.0 package repository on Ubuntu 24.04 LTS, with all Ubuntu security updates available on 2026-10-04 applied. Built by AdvanceCo's automated image pipeline: the image is hardened (root password locked, no SSH keys, shell history or cloud-init state from the build) and tested before release.

    Additional details

    Usage instructions

    Connect over SSH as the ubuntu user. Set your capture interface in /etc/suricata/suricata.yaml, run 'sudo suricata-update' to load rules, then 'sudo systemctl restart suricata'. For VPC Traffic Mirroring, allow UDP 4789 from your mirror sources. The recommended security group allows SSH and VXLAN only from 10.0.0.0/8; widen it if needed. Support: secproductsupport@advancecoinc.com 

    Support

    Vendor support

    Included support: email support from AdvanceCo's US-based engineering team during US business hours at secproductsupport@advancecoinc.com . Paid support options, including Slack, phone and response-time commitments, are available on request. More information:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Log Analysis
    Top
    50
    In Network Infrastructure, Operating Systems

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    3 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    11 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Network Intrusion Detection and Prevention
    Suricata 8 engine for passive intrusion detection via VPC Traffic Mirroring or inline intrusion prevention in AF-PACKET mode
    Multi-threaded Processing Architecture
    Multi-threaded engine that scales with instance vCPUs for concurrent traffic inspection
    Encrypted Traffic Visibility
    TLS and QUIC handshake visibility including SNI and JA3/JA4 fingerprints without decrypting traffic
    VXLAN Traffic Decoding
    VXLAN-encapsulated mirror traffic decoding capability for inspecting traffic from multiple instances without modification
    Network Traffic Analysis
    Signature-based detection via Suricata with full packet capture (PCAP) capability and protocol metadata extraction using Zeek or Suricata
    Host Visibility and Monitoring
    Elastic Agent for data collection with live queries via osquery and centralized management through Elastic Fleet
    File Analysis and Extraction
    File analysis and extraction capabilities via Strelka with support for rich protocol metadata and file extraction from network traffic
    Intrusion Detection and Deception
    Intrusion detection honeypots based on OpenCanary for enterprise visibility and threat detection
    Centralized Security Operations Console
    Native user interface (SOC) for alerting, detection, hunting, dashboards, case management, and grid management with support for standalone, single VM, or distributed grid deployment
    Stateful Firewall Inspection
    Fully featured stateful inspection firewall with advanced routing capabilities supporting dynamic protocols such as OSPF and BGP
    VPN Technologies
    Support for multiple VPN technologies including OpenVPN, IPsec, and Wireguard for securing cloud infrastructure
    Intrusion Detection and Prevention
    Inline intrusion detection and prevention system with high quality rulesets from Proofpoint including ET Open and ET Pro Telemetry editions
    Open Source License
    Open Source Initiative (OSI) approved 2-clause BSD license enabling open-source security platform deployment
    Modular Architecture
    Modularized and hardened architecture with simple and reliable firmware upgrades and fast adoption of upstream software updates

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.