pkg.sopackage field notes

brew / rank 3144

Install suricata with Homebrew

Network IDS, IPS, and security monitoring engine. Version 8.0.6 via Homebrew; verified 2026-07-08.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install suricata

provider-native install command

overview

Package summary

Network IDS, IPS, and security monitoring engine

Commands and aliases

  • suricata
  • suricata-update
  • suricatactl
  • suricatasc

history

Project history and usage

Suricata is an open-source network IDS, IPS, and network security monitoring engine developed by the Open Information Security Foundation. In package-manager culture it is a serious operational tool: installed from distro repositories, PPAs, source tarballs, and service packages, then fed rules and packet traffic.

Project history

Suricata's official timeline traces the first code to Victor Julien and Matt Jonkman in 2007, with William Metcalf joining shortly afterward. The first public beta arrived on New Year's Eve 2009, followed by the founding of OISF and the Suricata 1.0 release on March 1, 2010.

The project grew around an open foundation model, training, conferences, and recurring stable release lines. Official documentation describes Suricata as a high-performance IDS, IPS, and network security monitoring engine owned by a community-run non-profit foundation and developed by OISF.

Adoption history

Suricata is packaged broadly across Unix-like systems. The input package facts list Homebrew, Debian, Ubuntu, Fedora, Alpine, Arch, MacPorts, Nix, and openSUSE names; official download pages also publish source releases, Windows installers, Ubuntu PPA channels, and RPM packages.

Community adoption is also visible in OISF's timeline: public training began in 2013, SuriCon began in 2015, and later SuriCon events drew international users, developers, vendors, and security teams.

How it is used

Suricata is typically configured through `suricata.yaml`, run as a packet inspection service or command-line tool, and paired with rule management through `suricata-update`. The quickstart walks users through choosing interfaces, editing `/etc/suricata/suricata.yaml`, installing rules, restarting the service, and reading EVE JSON output.

Why package nerds care

Suricata matters to package nerds because it sits at the intersection of kernel packet capture, distro service management, ruleset updates, YAML configuration, JSON logs, and fast C/Rust-ish systems engineering. Installing the package is only the start; the interesting work is wiring rules, interfaces, logs, capabilities, and updates into a reproducible host setup.

Timeline

  • 2007: First Suricata code begins, according to the official timeline.
  • 2009: First public beta release occurs on New Year's Eve.
  • 2010: OISF is founded and Suricata 1.0 is released.
  • 2013: First public in-person Suricata training takes place.
  • 2015: First SuriCon is held.
  • 2025: Suricata 8.0.0 is released.
  • 2026: Official download page lists Suricata 8.0.5 and 7.0.16 as stable releases.

Related projects

  • Suricata is commonly compared or deployed alongside IDS/IPS and network-monitoring ecosystems such as Snort-style rules, Emerging Threats/Open rulesets, Zeek-style monitoring, packet capture tooling, SIEM pipelines, and JSON log processors such as jq.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for suricata. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
suricata.yaml/etc/suricata/suricata.yaml/usr/local/etc/suricata/suricata.yaml

executables

Installed executables

CommandKindExposureNote
suricataexecutableindexed executableDiscovered from the local executable index.
suricata-updateexecutableindexed executableDiscovered from the local executable index.
suricatactlexecutableindexed executableDiscovered from the local executable index.
suricatascexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version8.0.6
manager updated2026-07-08
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:suricata
Version8.0.6
Package managerHomebrew
Homepagehttps://suricata.io
Last updated2026-07-08T03:17:14Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation