Malcolm embeds Suricata as its signature-based detection engine, running it in IDS mode against live traffic or uploaded PCAPs and indexing all alerts into OpenSearch.
Suricata EVE JSON alert data can be visualized in Grafana via Elasticsearch or Loki, providing real-time security dashboards alongside OT metrics.
Suricata feeds network-level alerts into Wazuh for correlation with host-based events, creating a unified IT/OT security monitoring stack.