Read and triage Suricata IDS/IPS alerts from eve.json into a structured threat report — severity-ranked findings, attacker IPs, top triggered signatures, and recommended blocks. Use when you want an automated threat intelligence snapshot from your Suricata deployment, after a scan triggers alerts, or as a daily security briefing module. No external API. Reads your local Suricata log only.

Install

openclaw skills install @infectit007/suricata-monitor