---
title: "SELKS 10: The Next Big Leap for Open-Source Network Security"
description: Announcing SELKS 10! Boasting exciting new features like conditional packet capture and a revamped UI. Download SELKS 10 today and see for yourself!
image: https://www.stamus-networks.com/hubfs/StamusNetworks-SELKS10-Blog-FeaturedImage.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# SELKS 10: The Next Big Leap for Open-Source Network Security

 by [Peter Manev](https://www.stamus-networks.com/blog/author/peter-manev) | Jun 13, 2024 | [SELKS](https://www.stamus-networks.com/blog/tag/selks), [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Stamus Labs](https://www.stamus-networks.com/blog/tag/stamus-labs), [Clear NDR Community](https://www.stamus-networks.com/blog/tag/clear-ndr-community)

![](https://www.stamus-networks.com/hubfs/StamusNetworks-SELKS10-Blog-FeaturedImage.jpg)

Stamus Networks is pleased to announce the release and availability of SELKS 10 (now [Clear NDR - Community](https://www.stamus-networks.com/clear-ndr-community?hsLang=en)), the newest version of the popular Suricata-based IDS, NSM, and threat-hunting platform. This release marks the 10th anniversary of SELKS, which explains the jump from SELKS 7 to SELKS 10. To learn more about how SELKS has changed over the last 10 years, read our blog “[SELKS: 10 Years of Open-Source Network Defense](https://www.stamus-networks.com/blog/selks-10-years-of-open-source-network-defense?hsLang=en)''.

SELKS 10 is the most powerful version of SELKS yet, and we are only getting started. Read on to discover what’s new in this release, and as always, thank you for your continued support of our open-source work.

## **What is SELKS?**

As a reminder, SELKS is free, open-source, and turn-key Suricata network intrusion detection/protection system (IDS/IPS), network security monitoring (NSM), and threat-hunting implementation. Released under the GPLv3 license, SELKS is the perfect solution for small to medium-sized organizations, home network defenders looking for a capable and effective IDS and NSM system, or security practitioners looking to experiment with Suricata.

SELKS 10 includes 8 key components:

SELKS 10 is built on eight key components:

- [Suricata](https://suricata.io/) - Ready to use Suricata
- [Elasticsearch](https://www.elastic.co/products/elasticsearch) - Search engine
- [Logstash](https://www.elastic.co/products/logstash) - Log injection
- [Kibana](https://www.elastic.co/products/kibana) - Custom dashboards and event exploration
- [Stamus C.E. (formerly Scirius)](https://github.com/StamusNetworks/scirius) - Suricata ruleset management and Suricata threat hunting interface

Additionally, SELKS 10 utilizes functionality from [Arkime](https://arkime.com/), [Evebox](https://evebox.org/), and [CyberChef](https://gchq.github.io/CyberChef/), although those components were included after the “SELKS” acronym was established.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdFZLrqEB39Ac_FkMzNFrt_hHay94HbiNwuRE2njrdFDAPpxPFzRSp5TtefpeyjCVm1Zwd7V8k0j5eL_rZuW_17j8iz5OnoXt1ZLKvxom_WNPlFljMOOSU0Ro8meSypPptvU06SMujWp1migwUs4tazurLn?key=z2I75HlzKfg1tfnYVTDFQA)

## **What’s new in SELKS 10?**

There are four major updates to the SELKS system for version 10, and each one brings new benefits to users:

1. **1. Conditional packet capture****  
   ****  
   **SELKS users can now capture selected packets (PCAP) associated with detection events and then export those packets from the hunting interface. These PCAP files include the full session that triggered the detection in question. All PCAPs are de-duplicated, stored only once on the sensor, and made available for download as evidence or for playback into SELKS or third-party tools such as[Wireshark](https://www.wireshark.org/).
   
   The benefit of conditional packet capture is that it gives users access to critical network forensic data to be used for investigation, training, or threat intelligence sharing without dedicating the substantial storage resources needed for full-time packet capture.
2.  

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeR971npD55vcecJZWzIrh_xLHRpmzqeB7zA8uYxDzRUXKKLaPJG1qlh_9a8E_4ghGa0POuiif3gb_i_wNKMXr4XUcu-7rOKedYqtxXdLrPLzbZRbpLPTjbEGx4tl4x0W9IRqwwtH4YwcU0eo1YjPSRYaAG?key=z2I75HlzKfg1tfnYVTDFQA)

1. **2. User interface harmonized with Clear NDR - Enterprise****  
   ****  
   **Perhaps one of the biggest changes to SELKS 10 is an updated user interface in-line with the [Clear NDR - Enterprise](https://www.stamus-networks.com/clear-ndr?hsLang=en). The user interface (Stamus Community Edition or “Scirius”) now incorporates several of the latest capabilities of our commercial platform. Stamus CE is the first OSS GUI developed and dedicated specifically for Suricata and its data, and it now includes a more powerful and integrated hunting console, the ability to export evidence and artifacts, and additional pre-defined threat-hunting filters.
   
   This simplified user experience delivers consolidated threat detection, hunting, and evidence viewing and provides users with a streamlined way to zoom in and out of the data for rapid insights from millions of network security events.

 

New SELKS 10 hunting dashboard view:

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdCusK0FfHNS9MZzt5cSJSBpl2qn0VvGrLsm0uHXvYyGs0IhyrPiPqdur08O1KcXdzwvikavxCo_tdCdUMn-Qqe8Sof6xcCzgqKD7IqT_PfuYUoon6VID79Uv9yxOqpWoPTZl7XnGWaROW_lYbKBW95NbA_?key=z2I75HlzKfg1tfnYVTDFQA)

hunting dashboard view on a single event: 

![Single Event](https://www.stamus-networks.com/hs-fs/hubfs/Single%20Event.png?width=1200&height=630&name=Single%20Event.png)

Hunting dashboard with filter applied: 

![hunting dashboard with fiter](https://www.stamus-networks.com/hs-fs/hubfs/hunting%20dashboard%20with%20fiter.png?width=1200&height=823&name=hunting%20dashboard%20with%20fiter.png)

1. **3. Upgrade to Arkime version 5.0****  
   ****  
   **SELKS 10 adds the latest capabilities of Arkime - bulk search, improved session detail display, unified configs, unified authentication, additional multiviewer support, and offline PCAP retrieval improvements. Arkime augments Suricata's conditional packet capture to store and index network traffic in standard PCAP format. 

 

1. **4. Switch to PostgreSQL database****  
   ****  
   **SELKS 10 is now using a PostgreSQL database instead of SQLite to fix some issues, augment capabilities, improve scalability, and prepare for future evolution.

 

## **Download SELKS 10**

SELKS 10 can be obtained either from the[Stamus Networks SELKS homepage](https://www.stamus-networks.com/selks?hsLang=en) or from the[SELKS GitHub](https://github.com/StamusNetworks/SELKS/wiki/Docker).

Users have three options:

- [SELKS Docker Compose Package](https://github.com/StamusNetworks/SELKS/wiki/Docker) - Use the Docker Compose package to install SELKS in any LINUX environment and ensure you are including the very latest containers, including Evebox and Suricata.

- [Complete Image (ISO) with Desktop](https://my.stamus-networks.com/sn-dl/selks/c2c01b8f1fa39c61f9df253234e3dd2a851dc011ca21392d8e81a911390bc6b5/SELKS-10-desktop.iso) - Use the image with Desktop when you want a turnkey installation that includes the Debian x64 12 (Bookworm) Linux desktop environment. Can be deployed on bare metal hardware or VM.
- [Complete Image (ISO) without Desktop](https://my.stamus-networks.com/sn-dl/selks/a7d5dd09046d5887129d6ab8af01edf125f29880f81ad696055f624bc2e4187f/SELKS-10-no-desktop.iso) - Use the image without Desktop when you want a turnkey SELKS installation in a headless environment (based on Debian 12 Bookworm). Can be deployed on bare metal hardware or VM.

## **Upgrade from previous version of SELKS**

To upgrade the docker compose installation to the latest version of SELKS, follow the instructions here: [https://github.com/StamusNetworks/SELKS/wiki/Docker#upgrade-all-containers](https://github.com/StamusNetworks/SELKS/wiki/Docker#upgrade-all-containers).

We hope you enjoy SELKS 10, the most advanced SELKS system to date. As always, we encourage users to join the conversation over on our [Discord](https://discord.com/invite/h5mEdCewvn). To stay updated with new blog posts and other news from Stamus Networks, also make sure to subscribe to the [Stamus Networks Blog](https://www.stamus-networks.com/blog?hsLang=en) and the [Stamus Spotlight Newsletter](https://www.stamus-networks.com/stamusspotlightarchive?hsLang=en), and follow us on [Twitter](https://x.com/StamusN/), [LinkedIn](https://www.linkedin.com/company/stamus-networks/), and [Facebook](https://www.facebook.com/StamusNetworks/). 

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-10-the-next-big-leap-for-open-source-network-security%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-10-the-next-big-leap-for-open-source-network-security%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-10-the-next-big-leap-for-open-source-network-security%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-10-the-next-big-leap-for-open-source-network-security%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-10-the-next-big-leap-for-open-source-network-security%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fselks-10-the-next-big-leap-for-open-source-network-security%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Peter Manev](https://www.stamus-networks.com/hubfs/Stamus_Peter_Square-1.jpg)

#### Peter Manev

 Peter Manev is the co-founder and chief strategy officer (CSO) at Stamus Networks. He is a member of the executive team at Open Network Security Foundation (OISF). Peter has over 20 years of experience in the IT industry, including enterprise-level IT security practice. He is a passionate user, developer, and explorer of innovative open-source security software, and he is responsible for training as well as quality assurance and testing on the development team of Suricata – the open-source threat detection engine. Peter is a regular speaker and educator on open-source security, threat hunting, and network security at conferences and live-fire cyber exercises, such as Crossed Swords, DeepSec, Troopers, DefCon, RSA, Suricon, SharkFest, and others. Peter resides in Gothenburg, Sweden.

[**](https://www.linkedin.com/in/peter-manev-64918336/) [** ](https://twitter.com/pevma)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![](https://www.stamus-networks.com/hubfs/CVE-2026-CVE-2026-21510-11-Stamus%20Blog.jpg) ](https://www.stamus-networks.com/blog/detecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr?hsLang=en)

### [Detecting Attacks against CVE-2026-21510 and CVE-2026-21511 using Clear NDR](https://www.stamus-networks.com/blog/detecting-attacks-against-cve-2026-21510-and-cve-2026-21511-using-clear-ndr?hsLang=en)

This blog describes the steps Stamus Networks customers may take to determine if any of your...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.