NETWORK INTELLIGENCE

Overview

Offline
Events
0
0 / min
Throughput now
0 bps
IN 0 bps · OUT 0 bps
Observed traffic
0 B
TZSP bytes in selected range
Peak throughput
0 bps
Selected time range
Threats
0
0 incidents
Blocked
0
Policy actions

Traffic throughput

Total, inbound and outbound network speed sampled from TZSP traffic and retained in Redis.

loading
TotalInboundOutbound

Traffic direction

Inbound / outbound / internal

Events & alerts

Complete retained event history for the selected time range.

EventsAlerts

Event mix

Flow, DNS, TLS, HTTP and alerts

Top applications

Unique detected flows; failed/unknown classifications are excluded.

Top local clients

Traffic volume by monitored endpoint

Top remote peers

Traffic volume by external endpoint

Protocol anomalies
0
Parser / stream anomalies
DNS NXDOMAIN
0
Failed DNS resolutions
Encrypted sessions
0
TLS / QUIC / SSH
Cleartext sessions
0
HTTP / FTP / SMTP / Telnet
Local clients
0
Unique monitored endpoints
Remote peers
0
Unique external endpoints

Recent activity snapshot

Small bounded snapshot. Continuous live streaming is disabled until you start it.

TimeTypeSourceDestinationApplicationDetailsBytes

Live Sessions

Continuous streaming is off by default. Capture and Redis history continue independently.

Live off
The browser receives coalesced batches instead of every packet/update. Filters are applied server-side while live mode is active.
0 visible0 buffered0 batches/s0 UI drops
TimeTypeDirectionSourceDestinationProtocolAppDetailsBytes

Security incidents

Durable Suricata detections, analytics and security telemetry.

Last 24 hours
Alerts / 24h
0
Unique signatures
0
Sources / 24h
0
Filtered noise
0
Last seenHitsSeveritySignatureSourceDestinationAction

Top signatures

Most frequent detections in the selected traffic window

Alert severity mix

Suricata priority distribution

Detection coverage

Core IDS telemetry visible in the selected window

Encrypted client fingerprints

JA4 / JA3 / HASSH fingerprints observed in TLS, QUIC and SSH telemetry

Correlation identifiers

Flow/community IDs stay searchable in Live Sessions for cross-tool investigation.

Community IDindexed in history
Flow IDindexed in history
Transaction IDindexed in history

Observed asset identities

DHCP, ARP and passive Ethernet IP/MAC observations

File activity

Suricata fileinfo names and hashes when available

MikroSuricata NDR

Correlated incidents, asset behavior, threat intelligence and forensic evidence.

Open incidents
0
High risk ≥80
0
Known assets
0
IOC hits
0

Correlated incidents

Multi-stage evidence grouped around the affected local asset.

RiskLast seenAssetStagesATT&CKSummarySignalsStatus

Incident evidence

Select an incident.

TimeStageRiskATT&CKEvidence
No incident selected.

Asset intelligence

Passive Suricata identity enriched with RouterOS ARP/DHCP data.

RiskIPIdentityProtocolsOutbound portsAlertsLast seen

Add IOC

Saved persistently and synchronized into Suricata datasets.

Bulk IOC import

One indicator per line, or type,indicator,confidence,source,note.

Detection engines

Signals combined into NDR risk.

Suricata signaturesenabled
Threat intelligencedatasets + app matching
Behavior baselineapps / ports / identity
Beaconingperiodicity detector
DNS anomalyentropy / NXDOMAIN / tunnel
Lateral movementfan-out + xbits
MITRE ATT&CKnetwork-evidence mapping
Egress analyticslarge outbound transfers

Threat intelligence repository

IOC hits increase incident risk and remain persistent in SQLite.

TypeIndicatorConfidenceSeveritySourceHitsLast hit

Forensic PCAP ring

Persistent evidence mode is loading…

FileSizeModified

RouterOS blocks

Manual and automatic entries in the configured address-list.

Add block

Requires an authenticated session and RouterOS REST credentials.

Active address-list

RouterOS status not loaded.

AddressTimeoutCreatedCommentType

Reports

All report widgets use the global time range and are generated from the same backend snapshot.

Last 1 hourloading
Events
selected range
Traffic
observed bytes
Alerts
Suricata detections
Local clients
unique endpoints

Events over time

Alerts overlaid on total events

Protocols

Transport protocol distribution

Directions

Relative to monitored networks

Applications

Unique detected flows; failed/unknown classifications excluded.

Event types

EVE event distribution

Local clients

Endpoints inside monitored networks

Remote peers

External endpoints seen by local clients

Raw event sources

Unclassified source addresses for diagnostics

Signature Feeds

Download signatures from the OISF catalog or add an arbitrary public feed URL.

CatalogOISF suricata-update
ModeOISF free + manual URLs
Active merged rules
Automatic updateEvery 24h
ActivationValidated before reload

Add signature feed by URL

For sources not present in the public OISF list. The source is stored in persistent suricata-update state.

Providers and rulesets

Loading available signature sources…

Queue idle
SelectSourceVendorLicenseTagsStatusAction

Rules

Custom signatures, thresholds and suppressions.

Custom Suricata signatures

Validated before replacing the active ruleset.

Threshold / suppress

Noise controls and scoped suppression entries.

Merged public feed rules

Browse the active rules merged from all enabled signature feeds.

— active rules

Adaptive rule intelligence

Observed alert noise and concentration. Recommendations never disable signatures automatically.

NoiseSIDHitsIncidentsSignatureRecommendation
Open Rules to analyze recent signatures.

Ruleset snapshots

Local rules, thresholds, merged vendor rules and enabled source state.

CreatedReasonSize
No snapshots loaded.

System

Pipeline, storage and maintenance state.

Services

ComponentStatusDetails

Redis

Persistent traffic history and dashboard cache.

loading

Traffic history

Ports

ServiceDirectionProtocolAddressPortStatus

Maintenance

Destructive actions require an authenticated admin session.

Not signed in

Persistent backups

SQLite and IDS configuration only; Redis runtime data, logs and forensic PCAP are excluded.

CreatedFileSize
No backups loaded.

Audit log

Administrative actions recorded in SQLite.

TimeUserActionTargetResult
No audit events loaded.