Suricata IDS/IPS Inline: Tuning Without Killing Throughput
Running Suricata as more than a noisy alert firehose. IDS versus inline IPS modes, AF_PACKET and NFQUEUE deployment, ruleset management with suricata-update, and the threading and tuning that keep it from becoming the bottleneck.