The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alerts and packet capture management

Prev Next

The Suricata Sensor sends events to the configured syslog server. The Sensor uses the event-based packet capture mechanism defined in the Snort rule to capture PCAP files and store the packet logs on the Sensor.

Monitor alerts for Suricata Sensors

Monitoring the alerts helps you identify threats and verify that your security policies are working effectively. You can monitor alerts in a Syslog server. Configure the syslog server settings in the Manager to receive rule-match events. Suricata Sensors support multiple syslog configurations. For more information, see Configure a Syslog server.

Event-based packet capture for Suricata Sensors

Event-based packet capture allows you to capture network traffic data based on specific rule triggers.

You can configure the event-based packet capture by modifying the timemachine parameters in the Suricata YAML file.

timemachine:

# Enable the time machine feature to buffer packets on a best-effort basis. 
# The system flushes these packets to a pcap file when an alert is raised.
  enabled: yes

# Use the zerolenpkt-enabled flag to capture initial protocol handshake messages.
  zerolenpkt-enabled: yes

  # Specify the maximum memory per thread for the time machine. 
  # The memory per thread is the sum of the max-packet-size 
  # multiplied by the count of heap spaces for each heap within a thread.
  max-memory: 512mb

  # Specify the amount of pre-allocated heap space to generate. 
  # You can override this value for each heap.
  heap-prealloc-count: 5000

When a rule includes the ebc pcap keyword in the metatdata, the Sensor generates a packet capture file that you can fetch and store in the Manager database for analysis. This process provides the detailed visibility needed to investigate security incidents.

Example:

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any 
(msg:"GPL EXPLOIT CodeRed v2 root.exe access"; 
flow:established,to_server; 
http.uri; content:"/root.exe"; 
nocase; 
reference:url,www.cert.org/advisories/CA-2001-19.html; 
classtype:web-application-attack; 
sid:2101256; 
rev:12; 
metadata:created_at 2010_09_23, 
updated_at 2024_03_08, ebc pcap;)

The Manager supports downloading packet logs for specific alerts via API.

  • Storage on the Sensor: The Sensor stores PCAP files locally and embeds the corresponding alertid in the file name for mapping.

  • Transfer to the Manager: The Manager runs a scheduler every five minutes to fetch PCAP files via TFTP.

You can monitor the system status using show suricata stats all command.