Skip to content
A tools to work on suricata stats.log file.
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Type Name Latest commit message Commit time
Failed to load latest commit information.
doc Add example output in documentation Oct 14, 2015
src suristats: add EVE json file support Oct 14, 2015
LICENSE Add license file. Aug 1, 2012
README.rst Fix path to graph in documentation Oct 14, 2015 Fix typo in Oct 14, 2015
suri-graphite Add one shot run option to suri-graphite. Mar 15, 2013
suri-stats Fix -r option Oct 14, 2015




suri-stats is a small script based on ipython and matplotlib. It enables you to load a suricata stats.log file and/or JSON EVE file. Once this is done, it is possible to graph performance indicators.

Correlation of performance counters in Suricata


You can simply run

./ install


For a complete usage message, run

suri-stats -h

Interactive usage

Let's assume we've got a stats.log in /tmp/. Being in the suri-stats directory, one can run


You will be given a shell.

First thing to do is to create on Stats object

In [1]: ST=Stats("long run")
In [2]: ST.load_file("/tmp/stats.log")

To load a JSON file

In [1]: ST=Stats("modern run")
In [2]: ST.load_json_file("/tmp/stats.json")

This can take some time if the file is big.

You can also directly work on a file by running

suri-stats /tmp/stats.log

or for a JSON file

suri-stats -e /tmp/stats.log

The ST object will be created automatically.

Now, it is possible to list the retrieve counters

In [3]: ST.list_counters()

And you can now graph the value you want, successive call to plot will result in adding the graph on the output

In [4]: ST.plot('tcp.reassembly_memuse')
In [5]: ST.plot('capture.kernel_drops')

You can even save the file in a file

In [6]: savefig("correl.png")

In fact, you can use any function of matplotlib.

Handling stats file with multiple runs

If your statistics file contains the log for multiple suricata runs, you will be able to access to the different runs by using the .runs array of the Stats object. Each element of the array is one Stats object with the first element being the initial Stats object itself.

For example, to display the kernel drop for the two first runs

In <10>: print ST.runs[1].plot('capture.kernel_drops')
In <11>: print ST.runs[0].plot('capture.kernel_drops')

Command line operation

It is possible to output stats on a file

suri-stats -s -c decoder.pkts,decoder.ipv4,decoder.ipv6 -S  stats.log -v
Created ST object for run 'Run'
Loading stats.log file 'stats-short.log'

It is also possible to directly plot the result

suri-stats -p -c decoder.pkts,decoder.ipv4,decoder.ipv6 -S -o /tmp/out.png stats.log

You can also output the result other formats by changing the output extension. For example to have a PDF output

suri-stats -p -c decoder.pkts,decoder.ipv4,decoder.ipv6 -S -o /tmp/out.pdf stats.log

If your file contains multiple run, you can use -r flag to select it (count starting at 0).

The plot function

The stats are merged by default. But it is possible display on graph per-thread

In [7]: ST.plot("detect.alert", merge=False)

It is also possible to plot for one single thread

In [8]: ST.plot('tcp.sessions', 'AFPacketeth310')

To get the list of threads you can use

In [9]: ST.list_threads('tcp.sessions')

To start a new graph, you can use the clf() function or close the graph window.

To graph speed instead of raw data, you can use

In [10]: ST.plot('tcp.sessions', speed=True)

To graph normalized data instead of raw data, you can use

In [11]: ST.plot('capture.kernel_drops', normalized=True)
In [12]: ST.plot('decoder.tcp', normalized=True)

This will allow you to graph data with different scales on the same graph as both data are normalized.

Exporting data to graphite

suri-stats provide a script named 'suri-graphite' which can be used to sent suricata performance counters to a Graphite server. suri-graphite connect to Suricata unix socket and dump counters at a regular interval (suricata 1.4.1 or git necessary) and it sends this data to the Graphite server specified by -H flag.

You can’t perform that action at this time.