RouterOS Suricata TZSP
TZSP → TAP → Suricata → EVE JSON → SQLite
Loading…
TZSP datagrams
0
Frames to TAP
0
Alert hits
0
Incidents
0
Alerts / 24h
0
RouterOS blocks
0
Filtered noise
0
Deduplicated
0
Detection profile
Loading tuning configuration…
Rules in the image
Loading rule status…
The reserved self-test SID 1000001 only matches the explicit TZSP test payload and is filtered from the incident database. Production detections use separate SIDs.
Recent incidents
Repeated matches are aggregated into one incident window.| Last seen | Hits | Severity | Signature | Source | Destination | Action |
|---|
Extended statistics
| Top signatures / 24h | ||||
|---|---|---|---|---|
| SID | Signature | Severity | Hits | |
| Top sources / 24h | ||
|---|---|---|
| Source | Hits | Last seen |
| Top destinations / 24h | ||
|---|---|---|
| Destination | Hits | Last seen |
| Severity distribution | |
|---|---|
| Severity | Hits |
| Sensor counter | Value |
|---|
| Suricata counter | Value |
|---|
System status
| Component | Status | Details |
|---|
Ports
| Service | Direction | Protocol | Address | Port | Status |
|---|
Database & storage
Loading database/storage state…
Rules & signature feeds
The image contains an ET/Open snapshot plus conservative local production rules. Downloaded feeds and their enabled-source configuration are persisted in
/var/lib/suricata. Every downloaded ruleset is validated with suricata -T before it replaces the last known-good rules.Signature sources
Load the OISF source catalog to manage feeds.The table is populated by
suricata-update list-sources --free from the official OISF source index. ET/Open is the default feed. Other free feeds can be enabled individually; sources requiring parameters are shown but are not enabled blindly from the UI.| Source | Vendor | License | Tags | Status | Action |
|---|---|---|---|---|---|
| Source catalog not loaded yet. | |||||
Custom Suricata signatures
Use SIDs 1001000+ for site-specific detections. Built-in production rules are maintained by the image.
threshold.config / suppressions
Global suppress removes alerts for a SID. Prefer source/destination-scoped suppression or rate limits when only one host is noisy.
Maintenance
Destructive actions require
ADMIN_TOKEN. The token is kept only in this browser session.