Suricata integrations, in detail.

Documented exchange with Suricata, such as rule output or event ingestion. Read the profile for the precise scope.

Filter these tools

Check the actual function

Each entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.

Before you connect it

Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.

4 tools with documented Suricata integration evidence.

T-Pot

Detection and monitoring · Germany

Read the tool profile

Documented support

Provides a Suricata container alongside honeypots for network security monitoring. Availability depends on the selected deployment configuration.

Tenzir

Feed automation · Germany

Read the tool profile

Documented support

The read_suricata operator parses Suricata EVE JSON from files or streams into structured events. This is log ingestion, not execution of Suricata detection rules.

A missing tool may support this feature without having been checked in this research pass.

Send a source or correction