In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | In Oracle certification review |
|---|
| Version | 7.0.16 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp) |
|---|
| Category | Security |
|---|
| Upstream licence | GPL-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- Suricata runs as a systemd service in IDS mode on the primary network interface, bound automatically at first boot (its name is written into the af-packet section of /etc/suricata/suricata.yaml). It opens no TCP or UDP port; the host firewall permits SSH only. Check status:
sudo systemctl status suricata
- Smoke-test from the instance: engine version, the interface being captured, and its packet counters:
suricata -V
sudo suricatasc -c iface-list
sudo suricatasc -c iface-stat <interface>
- Prove detection end to end: fetch a harmless test page whose reply matches ET Open rule 2100498, then look for the alert:
curl -s http://testmynids.org/uid/index.html
sudo grep 2100498 /var/log/suricata/fast.log
Expect a "GPL ATTACK_RESPONSE id check returned root" line. Alerts: /var/log/suricata/fast.log. All events as JSON: /var/log/suricata/eve.json.
- Detection rules refresh daily via suricata-update.timer, which downloads the ET Open ruleset and reloads the engine. Run that same refresh now:
sudo systemctl start suricata-update
- To inspect traffic for other hosts, mirror it here with an OCI VTAP: its target is a network load balancer with a UDP 4789 listener and this instance as a backend. Mirrored packets arrive VXLAN-encapsulated on UDP 4789, which Suricata decodes natively. In your VCN security list permit UDP 4789 from the load balancer's subnet only, restrict SSH (22) to your admin CIDR, and never expose either to the internet. No host-firewall change is needed: AF_PACKET capture sees packets before the firewall filters them.
- To monitor a different interface, change the first "- interface:" line under af-packet: in /etc/suricata/suricata.yaml, then validate and restart:
sudo suricata -T -c /etc/suricata/suricata.yaml
sudo systemctl restart suricata
Rules and update state live in /var/lib/suricata; logs in /var/log/suricata. Size at 2 OCPU (4 vCPU) and 16 GB memory minimum; add OCPU with monitored throughput.
The image is CVE-patched at build time. Apply ongoing updates, including Suricata fixes from EPEL, with:
sudo dnf -y update
What the image provides
- Suricata 7.0.16, installed from the Oracle Linux 9 EPEL repository, running as a dedicated service in intrusion-detection mode.
- A pure network sensor. Suricata listens on no TCP port of its own; it inspects traffic on the instance's interface, which the image binds automatically on first boot. The host firewall permits only SSH — nothing else is exposed.
- Detection rules current as of build, with a daily systemd timer that refreshes the rule set and reloads the engine, so signatures stay up to date between image rebuilds.
- Security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny, no account with a usable password, no stray keys, and the image fully patched at build time.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Suricata is a registered trademark of the Open Information Security Foundation (OISF). This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by OISF. Suricata is distributed under the GNU General Public License v2; this image redistributes it unmodified.