We have published pre-built Linux packages for Suri Oculus 4.0, our network security monitoring and analysis platform built around Suricata.
The goal of Suri Oculus is to provide an additional layer for working with Suricata data: event monitoring and visualization, network activity analysis, host behavior analysis, and AI-assisted anomaly detection.
Supported distributions
Suri Oculus 4.0 packages are currently available for:
Debian 12
Debian 13
Ubuntu 22.04 LTS
Ubuntu 24.04 LTS
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Fedora 42
Fedora 43
Fedora 44
Both RPM and DEB packages are provided, depending on the distribution.
Suri Oculus components
The current package set includes:
daemonmove – Suricata event processing and aggregation service
oculus-tools – system and maintenance utilities
suri-oculus-cpp-server – C++ backend and REST API
suri-oculus-front – web interface for monitoring and visualization
pistache – runtime library used by the C++ backend
pistache-devel – development files for Pistache
One of the areas we have been working on for Suri Oculus 4.0 is HBF (Host Behavior Fingerprinting).
HBF builds behavioral information for hosts observed in Suricata traffic. It aggregates information such as network activity, protocols, destination ports, DNS activity, TLS/SNI data, alerts, and other host-related statistics. This makes it possible to examine a host not only through individual Suricata events, but also through its accumulated network behavior.
Suri Oculus also includes an anomaly-analysis layer that uses data collected from Suricata for additional behavioral analysis.
Installation
The purpose of publishing native packages is to make deployment easier and avoid requiring users to manually build the Suri Oculus components and their dependencies.
Packages, checksums, signatures, and installation information are available on the project website:
Suri Oculus remains closely tied to the Suricata ecosystem, and feedback from Suricata users is particularly useful. Testing reports, compatibility issues, suggestions regarding HBF, and observations from real Suricata deployments are welcome.