I would like to use suricata as IDS for AWS VPC flow logs (offline mode). Anyone implemented already or any other IDS suitable for this scenario.
Thanks in advance
I would like to use suricata as IDS for AWS VPC flow logs (offline mode). Anyone implemented already or any other IDS suitable for this scenario.
Thanks in advance
Suricata folks wrote a collaboration walk-through of sorts on how to setup Suricata in an AWS VPC environment. Maybe that could be useful for other people who happen to stumble upon this question in the future: https://aws.amazon.com/blogs/opensource/scaling-threat-prevention-on-aws-with-suricata/