SimpleNSM - Suricata & EveBox Simply

SimpleNSM is a tool to easily run Suricata and EveBox on Linux systems using Docker or Podman.

This program is considered experimental and many things may change, break, change name, change repo, etc, etc... And I might even force push!

System Requirements

In order to use SimpleNSM you will need a Linux machine that has a network interface that is already seeing the traffic you want to monitor. In the simplest of scenarios, this could be the primary network interface on your Linux machine that only sees the traffic to and from that machine itself.

As for the Linux machine itself, it could be any x86_64, Arm32 or Arm64 Linux machine that has a working installation of Docker or Podman, which should be just about any Linux distribution actively maintained in 2023.

You will also need root access, as that is a requirement for Suricata to get the low level access it needs to network interfaces.

Installation the Easy Way

mkdir ~/simplensm
cd ~/simplensm
curl -sSf | sh

Or download directly from

Once you have the program downloaded, run it:


Under the configure menu select your network interface, select "Start" from the main menu then point your browser at

External Access

If running SimpleNSM on something like your Linux based firewall, router or server you may want to explore the menu options for enabling external access.

