Suricata 8 network intrusion detection and prevention on a hardened, fully patched Ubuntu 24.04 LTS AMI. Inspect traffic from Amazon VPC Traffic Mirroring or inline, send EVE JSON events to your SIEM, and manage rules with suricata-update. Maintained by AdvanceCo with US-based email support.
Suricata is the open-source network threat detection engine developed by the Open Information Security Foundation (OISF). This AMI from AdvanceCo packages Suricata 8 on Ubuntu 24.04 LTS so you can start inspecting AWS network traffic without building and maintaining the sensor yourself.
What is included
Suricata 8.0.x from the official OISF package repository, pinned to the 8.0 release series
Ubuntu 24.04 LTS with all available security updates applied when the image is built
suricata-update for downloading and refreshing rule sets such as ET Open
A systemd service unit for running Suricata as a service
A hardened image: root password locked, and no SSH keys, shell history or cloud-init state carried over from the build
How you can use it
Passive IDS with Amazon VPC Traffic Mirroring: Suricata decodes VXLAN-encapsulated mirror traffic, so one sensor can inspect traffic from other instances without changing them.
Inline IPS: run Suricata in AF-PACKET inline mode on an instance that routes traffic, and drop traffic that matches your rules.
Network security monitoring: EVE JSON logs record alerts plus protocol metadata for HTTP, DNS, TLS, QUIC, SMB, SSH and more, ready to ship to Amazon CloudWatch Logs, Amazon OpenSearch Service or a third-party SIEM.
Compliance evidence: network intrusion detection is a common control in frameworks such as PCI DSS, and Suricata's logs can support the evidence you provide for it.
What Suricata 8 brings
A multi-threaded engine that scales with instance vCPUs
TLS and QUIC handshake visibility, including SNI and JA3/JA4 fingerprints, without decrypting traffic
New and expanded protocol parsers, including LDAP
Maintenance and support
AdvanceCo rebuilds this AMI with current Ubuntu security patches and the latest Suricata 8.0 point release, and publishes updates as new versions of this listing. Included support is by email during US business hours from our US-based team. Paid support with Slack, phone and response-time commitments is available on request.
Getting started
Launch the AMI and connect over SSH as the ubuntu user. Set your capture interface in /etc/suricata/suricata.yaml, run suricata-update to load rules, then restart the suricata service. For Traffic Mirroring, allow UDP 4789 from your mirror sources in the instance security group.
Highlights
Suricata 8 on Ubuntu 24.04 LTS: OISF packages pinned to the 8.0 series, with all Ubuntu security updates applied and the image hardened before release.
Built for AWS traffic inspection: VXLAN decoding lets one sensor inspect traffic from Amazon VPC Traffic Mirroring, or run it inline in AF-PACKET IPS mode.
SIEM-ready EVE JSON logging: alerts and protocol metadata for HTTP, DNS, TLS, QUIC, SMB and more, with US-based support from AdvanceCo.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Suricata 8 IDS/IPS on Ubuntu (Hourly) by AdvanceCo
You pay by the hour based on the EC2 instance type you run Suricata on. Each dimension maps to one instance size, so the software bills the same way across all choices. Pricing scales with the compute you select. Options range from small instances like m7a.medium and t3.large up to large and bare-metal types such as m8i.metal-96xl and m8id.metal-48xl. The m8i, m8id, and m8i-flex families offer general-purpose sizing, while m7a, m7i, c-series, and older m-series instances add alternatives. You choose the instance that matches your network traffic and performance needs.
Top-of-mind questions for buyers
What does one hourly unit cover for billing purposes?
Each dimension bills one running EC2 instance of that type per hour. You pay the software rate for every hour the instance runs. One unit equals one instance-hour, so cost scales with how many instances you run and how long each stays active.
Am I charged when the instance is stopped?
Software charges meter running instance-hours only. A fully stopped instance stops accruing the software rate. You may still pay underlying AWS fees for attached storage or reserved capacity, but the Suricata software license counts active running time.
How does the hourly option compare to running continuously?
Hourly billing meters actual instance-hours with no upfront commitment, so cost tracks usage directly. This suits variable or test workloads where instances start and stop. For instances running around the clock, hours accumulate steadily and cost reflects continuous operation.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Update to patch copy fail
Additional details
Usage instructions
SSH in as ubuntu.
Support
Vendor support
Included support: email support from AdvanceCo's US-based engineering team during US business hours at secproductsupport@advancecoinc.com.
Paid support options, including Slack, phone and response-time commitments, are available on request.
More information:
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Suricata 8 network intrusion detection and prevention on a hardened, fully patched Ubuntu 24.04 LTS AMI. Inspect traffic from Amazon VPC Traffic Mirroring or inline, send EVE JSON events to your SIEM, and manage rules with suricata-update. Maintained by AdvanceCo with US-based email support.
Suricata 8 network intrusion detection and prevention on a hardened, fully patched Ubuntu 24.04 LTS AMI. Inspect traffic from Amazon VPC Traffic Mirroring or inline, send EVE JSON events to your SIEM, and manage rules with suricata-update. Maintained by AdvanceCo with US-based email support.
OpenCanary honeypot on a hardened Ubuntu 22.04 LTS AMI. Run low-interaction decoy services such as SSH, FTP, HTTP, RDP and MySQL inside your VPC and get alerted when anything connects to them. Maintained by AdvanceCo with US-based email support.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.