Featuring Trisul 6.5 - Network Security Monitoring and Deep Traffic Analytics
50K+
This Docker Image contains a full blown NSM (Network Security Monitoring) system as well as deep Network Traffic Analytics.
New Release 07-Jan-2020: Latest release with many updates and enhancements release notes
New Release 21-Feb-2019: New GeoIP support, Crosskeys counters to monitor a cross product of two or more metrics, fixes to docker scripts release announcement
New Release 05-Jul-2018: Must more stable , improved performance upto 400Mbps per CPU Core for full NSM functionality, faster LuaJIT engine. release announcement
New Release 27-Feb-2018 : Now includes SNMP tools and --fine-resolution option for 1-sec time series
The image includes the latest TrisulNSM 6.5 in a single node configuration. The appliance contains a single Probe, a single Hub, and a Web Trisul. A fine tuned database is also included that is capable of handling very large networks (try it and see if you can overwhelm it).
The image includes Suricata IDS paired with Emerging Threats community rules updated via Oinkmaster. This supplies the IDS context to the system. Trisul provides everything else like 200+ Traffic Metrics, PCAP storage and recall, flow analysis, meta dataextraction and a programmable LUA API.
This is the easiest way to get rolling with Traffic+NSM for total visibility. The best part is the docker image packs into it a FREE Trisul License that lets you monitor a rolling 3-day window for ever. Upgrade to a any license to unlock the restriction.
Just get going !!
sudo docker run --name=trisul1a --net=host \
-v /opt/trisuldata:trisulroot \
-d trisulnsm/trisul6 --interface eth0
Go to localhost:3000
Done!
For more details check out trisulnsm/docker@github

There are other options to running the docker image. Please refer to the trisulnsm/docker GitHub page for more
Content type
Image
Digest
Size
586 MB
Last updated
almost 5 years ago
docker pull trisulnsm/trisul6