Overview
Traffic throughput
Total, inbound and outbound speed from the Rust TZSP data-plane; 1 s samples are retained in Redis.
Traffic direction
Inbound / outbound / internal
Events & alerts
Complete disk-backed event history for the selected time range.
Event mix
Flow, DNS, TLS, HTTP and alerts
Top applications
Unique detected flows; failed/unknown classifications are excluded.
Top local clients
Traffic volume by monitored endpoint
Top remote peers
Traffic volume by external endpoint
Recent activity snapshot
Small bounded snapshot. Continuous live streaming is disabled until you start it.
| Time | Type | Source | Destination | Application | Details | Bytes |
|---|
| Time | Type | Direction | Source | Destination | Protocol | App | Details | Bytes |
|---|
| Last seen | Hits | Severity | Signature | Source | Destination | Action |
|---|
Top signatures
Most frequent detections in the selected traffic window
Alert severity mix
Suricata priority distribution
Detection coverage
Core IDS telemetry visible in the selected window
Encrypted client fingerprints
JA4 / JA3 / HASSH fingerprints observed in TLS, QUIC and SSH telemetry
Correlation identifiers
Flow/community IDs stay searchable in Live Sessions for cross-tool investigation.
Observed asset identities
DHCP, ARP and passive Ethernet IP/MAC observations
File activity
Suricata fileinfo names and hashes when available
Correlated incidents
Multi-stage evidence grouped around the affected local asset.
| Risk | Last seen | Asset | Stages | ATT&CK | Summary | Signals | Status |
|---|
Incident evidence
Select an incident.
| Time | Stage | Risk | ATT&CK | Evidence |
|---|---|---|---|---|
| No incident selected. | ||||
Asset intelligence
Passive Suricata identity enriched with RouterOS ARP/DHCP data.
| Risk | IP | Identity | Protocols | Outbound ports | Alerts | Last seen |
|---|
Add IOC
Saved persistently and synchronized into Suricata datasets.
Bulk IOC import
One indicator per line, or type,indicator,confidence,source,note.
Detection engines
Signals combined into NDR risk.
Threat intelligence repository
IOC hits increase incident risk and remain persistent in SQLite.
| Type | Indicator | Confidence | Severity | Source | Hits | Last hit |
|---|
Forensic PCAP
Persistent evidence mode is loading…
| File | Size | Modified |
|---|
Add block
Requires an authenticated session and RouterOS REST credentials.
Active address-list
RouterOS status not loaded.
| Address | Timeout | Created | Comment | Type |
|---|
Events over time
Alerts overlaid on total events
Protocols
Transport protocol distribution
Directions
Relative to monitored networks
Applications
Unique detected flows; failed/unknown classifications excluded.
Event types
EVE event distribution
Local clients
Endpoints inside monitored networks
Remote peers
External endpoints seen by local clients
Raw event sources
Unclassified source addresses for diagnostics
Add signature feed by URL
For sources not present in the public OISF list. The source is stored in persistent suricata-update state.
Providers and rulesets
Loading available signature sources…
| Select | Source | Vendor | License | Tags | Status | Action |
|---|
Custom Suricata signatures
Validated before replacing the active ruleset.
Threshold / suppress
Noise controls and scoped suppression entries.
Merged public feed rules
Browse the active rules merged from all enabled signature feeds.
— active rules
Merged public feed rules
Browse the active rules merged from all enabled signature feeds.
Adaptive rule intelligence
Observed alert noise and concentration. Recommendations never disable signatures automatically.
| Noise | SID | Hits | Incidents | Signature | Recommendation | |
|---|---|---|---|---|---|---|
| Open Rules to analyze recent signatures. | ||||||
Ruleset snapshots
Local rules, thresholds, merged vendor rules and enabled source state.
| Created | Reason | Size | |
|---|---|---|---|
| No snapshots loaded. | |||
Services
| Component | Status | Details |
|---|
Redis
Persistent traffic history and dashboard cache.
Traffic history
Ports
| Service | Direction | Protocol | Address | Port | Status |
|---|
Maintenance
Destructive actions require an authenticated admin session.
Persistent backups
SQLite and IDS configuration only; Redis runtime data, logs and forensic PCAP are excluded.
| Created | File | Size | |
|---|---|---|---|
| No backups loaded. | |||
Audit log
Administrative actions recorded in SQLite.
| Time | User | Action | Target | Result |
|---|---|---|---|---|
| No audit events loaded. | ||||