Suricata — Network Integration
Architecture
Network Traffic
│
▼
Suricata IDS
│ file extracted from traffic
├──► Stores file at: <suricata_path>/<sha256[0:2]>/<sha256>
└──► Publishes JSON to Redis key
│
▼
suricata client
│ polls Redis LPOP
│ queries highvolt-server (dedup)
│ submits file for analysis
▼
highvolt-server → LLM → OpenSearchHow it works
Suricata configuration requirements
Configuration (via JSONAir)
Debug flags
Flag
What it logs
Submitted JSON structure
Last updated