Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Suricata

In Oracle review

DCA Hardened IDS/IPS for Suricata — Support & Quick Start

A hardened, CVE-patched virtual machine image running Suricata — the open-source, high-performance network intrusion detection and prevention engine (IDS/IPS) — on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version7.0.16
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp)
CategorySecurity
Upstream licenceGPL-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. Suricata runs as a systemd service in IDS mode on the primary network interface, bound automatically at first boot (its name is written into the af-packet section of /etc/suricata/suricata.yaml). It opens no TCP or UDP port; the host firewall permits SSH only. Check status:
    sudo systemctl status suricata
  3. Smoke-test from the instance: engine version, the interface being captured, and its packet counters:
    suricata -V
    sudo suricatasc -c iface-list
    sudo suricatasc -c iface-stat <interface>
  4. Prove detection end to end: fetch a harmless test page whose reply matches ET Open rule 2100498, then look for the alert:
    curl -s http://testmynids.org/uid/index.html
    sudo grep 2100498 /var/log/suricata/fast.log

    Expect a "GPL ATTACK_RESPONSE id check returned root" line. Alerts: /var/log/suricata/fast.log. All events as JSON: /var/log/suricata/eve.json.

  5. Detection rules refresh daily via suricata-update.timer, which downloads the ET Open ruleset and reloads the engine. Run that same refresh now:
    sudo systemctl start suricata-update
  6. To inspect traffic for other hosts, mirror it here with an OCI VTAP: its target is a network load balancer with a UDP 4789 listener and this instance as a backend. Mirrored packets arrive VXLAN-encapsulated on UDP 4789, which Suricata decodes natively. In your VCN security list permit UDP 4789 from the load balancer's subnet only, restrict SSH (22) to your admin CIDR, and never expose either to the internet. No host-firewall change is needed: AF_PACKET capture sees packets before the firewall filters them.
  7. To monitor a different interface, change the first "- interface:" line under af-packet: in /etc/suricata/suricata.yaml, then validate and restart:
    sudo suricata -T -c /etc/suricata/suricata.yaml
    sudo systemctl restart suricata

    Rules and update state live in /var/lib/suricata; logs in /var/log/suricata. Size at 2 OCPU (4 vCPU) and 16 GB memory minimum; add OCPU with monitored throughput.

The image is CVE-patched at build time. Apply ongoing updates, including Suricata fixes from EPEL, with:

sudo dnf -y update

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Suricata is a registered trademark of the Open Information Security Foundation (OISF). This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by OISF. Suricata is distributed under the GNU General Public License v2; this image redistributes it unmodified.