Loading...

Manage your Suricata fleet from one place — including the Suricata you already run.

IDSTower deploys, configures, monitors and manages rules for Suricata clusters at scale. Point it at hosts already running Suricata and it detects your instances, backs up your configuration, and takes over only the capabilities you choose — monitoring first, full management when you're ready.

No signup — the demo credentials are pre-filled for you.

IDSTower Cluster Summary

Adopt incrementally. Keep what you own.

You don't hand over your production IDS on day one. Onboard an existing cluster and choose which of six capabilities IDSTower manages — each independent, each changeable at any time.

Health Monitoring

Metrics, service status and resource usage from your hosts.

Rules Management

Push IDS rules and threat-intelligence indicators to your sensors.

Log Management

Clean up Suricata logs by retention period and disk usage.

Service Control

Start, stop and restart the Suricata services.

Package Management

Install and upgrade the Suricata and Filebeat versions.

Configuration Management

Own and deploy suricata.yaml and the cluster's configuration profile.

Start with monitoring only, so IDSTower changes nothing on your hosts. Add rules management when you trust it. Hand over suricata.yaml last — and a backup of your existing configuration is taken before anything changes, either way.

How onboarding works What each capability controls
Single GUI
Single Interface

Manage multiple Suricata clusters with 10's of hosts from a single, easy-to-use GUI.

Configure with ease
Configure with ease

Configure any Suricata option without the need to edit text files.

Get faster results
Get faster results

Stop duct taping right and left, automate your IDS operations, reduce human error and provision IDS clusters in minutes.

Exploit the real power of Open Source IDS

Thousands of companies around the world use Suricata IDS/IPS to defend their networks.

Why choose IDSTower?

Manage Suricata IDS Clusters with ease, Provision, Configure & Monitor Clusters through an intuitive, easy-to-use web interface.

Image placeholder
Provision a Cluster in minutes — or adopt one you already have

a step-by-step wizard for installing Suricata across many hosts at once, with multiple repositories to install packages from, including deploying to offline machines using the built-in packages repository, or your own custom-built packages. Already running Suricata? Point the wizard at those hosts instead and IDSTower onboards them as they are, without reinstalling anything.

Image placeholder
Manage Configurations Centrally

Central management for starting, stopping and configuring Suricata & the logshipper (Filebeat) across the entire cluster, with a full history of all configuration changes, so you can revert back to them with a single click.

Image placeholder
Health monitoring

Collects key suricata metrics, hosts health metrics, loaded & failed rules and display them in one web interface.

why IDSTower

Powerful Rules Management Interface

Manage your IDS Ruleset through a centralized web Interface, with a powerful search & filtration features.

Image placeholder
Import thousands of rules

Enable a Rules feed or manually import Rules from multiple files at once, while intelligently expiring old rule revisions and enabling the new ones, saving you precious time & effort to keep your rules updated.

Image placeholder
Deploy rules updates automatically

Each Suricata host is integrated with IDSTower to periodically checks for rules updates & apply them automatically.

Image placeholder
Organize Ruleset like a pro!

Manage rule life-cycle using rule status, organize them into custom categories, add custom tags\metadata to them to add more context for analysts, all without editing a single text file.

Image placeholder
Export rules to suricata-update, OPNsense & more.

Export IDSTower-Managed rules/IOCs to external Suricata installations or other systems in text, STIX2.1 format and more.

Powerful Rules Management Interface

Intelligent Rules Parsing & Transformation

IDSTower lets you customize rule via the rule editor, and will parse and validate the rule syntax automatically, while intelligently inserting the changes you set to the final rule sent to the hosts.

Image placeholder
No Text files!

Edit all of your rules through the web GUI, change the source code, set the category and even add tags to add more context to your analyst.

Image placeholder
Tune Options without touching code

Set Rule Priority, Target and other options without editing the rule source code!, all the changes you set through the UI will be intelligently inserted into the final rule.

Image placeholder
Do the tuning once, keep it forever

When you customize a rule through rule options, IDSTower will make sure to copy those customizations to the new rule revisions.

IDSTower Rules Editor

Integrated Threat Intelligence Engine

Enable Commercial & Open Source Threat Intelligence Feeds with a single click!, now with 14 pre-integrated Rules & IOCs Feeds and generic feeds support including TAXII\STIX, MISP and more!.

Image placeholder
Ingest thousands of Indicators

IDSTower will ingest Thousands of Indicators of Compromise from enabled feeds, extract their associated metadata, assign them a score, set an expiration date & expire them when they are no longer present in the feed, all automatically!

Image placeholder
Deploy Indicators updates automatically

Each Suricata host is integrated with IDSTower to periodically checks for Indicators updates & apply them automatically.

Image placeholder
Pre-Configured Alerts

All enabled indicators will be alerted on when they are detected in the monitored network traffic without you having to write any rules.

Powerful Rules Management Interface

Excellent Pricing Plans

Standard
Free
  • Provision a Cluster in minutes
  • Onboard an existing Suricata deployment
  • Manage Configurations Centrally
  • Suricata Health monitoring
  • 14 Integrated Threat Intelligence feeds
  • TAXII/STIX, MISP & generic feeds support
  • Powerful Rules & IOCs Management
  • Intelligent Rules Parsing & Transformation
  • 1 Suricata instance, self-supported
Get Free License now
Professional
$499
Per Suricata instance per year
Buy Now! Get a Free 30-day Trial
Enterprise
Let's talk
  • Includes all Professional Features
  • Role-Based Access Control (RBAC)
  • Multi-Instance Architecture
  • AWS Network Firewall Connector
  • Fully Managed Cloud Instances
  • Custom Features Development
  • Professional Services
  • Custom Support SLA
Let's talk Get a Free 30-day Trial

A license is counted in Suricata instances. On the Free and Professional tiers each host runs a single instance, so one host = one instance. The Enterprise tier allows several instances on the same host, and each instance counts toward your licensed number.

Helpful answers

Manage Suricata hosts effectively, save time and money by automating manual work.

When you buy the professional, you will get email support with it, you can contact us at any time for issues concerning IDSTower, The Enterprise license offers tailored support as per the customer needs.

We encourage you to test out IDSTower before buying it to make sure it fits your needs, that is why we offer a Free 30-day Trial (no credit card required!).

If 30 days are not enough, please contact us and we'd love to help you out!

Installation no longer asks for a license key. IDSTower starts without one, and the first administrator to log in is taken to an activation page where the key is pasted in. You can also set or change it later from Settings → License.

For Docker and automated deployments, the key can be provisioned non-interactively with the --set-license-key option, so no configuration file has to be edited.

IDSTower runs on Ubuntu, Debian, RHEL, AlmaLinux, Rocky Linux, Oracle Linux and Amazon Linux, and can also be run as a Docker container. Please refer to the system requirements section for the supported versions, each with its own step-by-step installation guide.

The IDSTower installation wizard offers three different installation sources, one of which is your own custom packages repository. All you need to do is place your custom-built Suricata packages on the IDSTower machine and you are ready to go. See using custom-built packages in our documentation for the details.

If your Suricata is already installed and you would rather not have IDSTower package or reinstall it at all, you can onboard the existing installation instead and leave Package Management switched off.