Powered by Zoomin Software. For more details please contactZoomin

Flowmon User Guide

Configuration in the Flowmon User Interface

  • Last Updated: September 16, 2026
  • 2 minute read
    • Flowmon Products
    • Flowmon
    • Documentation

This section contains an additional description of the basic settings that you can configure directly in the Flowmon user interface. For more advanced tuning of the Suricata IDS system (for example, false positive tuning or Suricata rules management), continue to the Configuration in the command line section.

The settings can be found in the Flowmon Configuration Center, under the section Monitoring Ports (in the left menu). On this page, it is possible to set the global settings for all interfaces or configure individual interfaces by selecting the IDS probe tab in the respective section. The global settings are always applied to all interfaces that do not have an individual configuration set.

Following the IDS Probe Installation and Setup, the IDS should be enabled for all monitoring interfaces. The IDS can be enabled globally for all monitoring ports using the global settings, or for individual monitoring ports overriding the global settings with custom settings. Both is also possible — enable globally and selectively disable or enable individual ports — using the Enabled toggle under the IDS Probe tab.

As mentioned above, it is possible to set the individual configuration for each interface when the global setting is not convenient for some reason. You can enable this using the Use custom settings toggle. If this toggle is enabled, two more options are displayed - Filter and Packet count.

You can use the first option (called Filter) to enable packet filtering and specify which packets should be processed by the Suricata IDS. The filter can contain one predefined filter. For more information about filters, see IDS Probe filters.

As mentioned in the Suricata IDS Configuration and Tuning section, only the first N packets from each session (per bi-flow) are passed to the Suricata IDS system for inspection. You can adjust this value by using the Packet count option. By default, this value is set to 10 packets (that is, 5 packets from both directions). The value can be in the range of 3-100 packets.

In the following screenshot, you can see the configuration of the IDS probe in the Flowmon Configuration Center:

You can start or stop the IDS Probe using the Flowmon Configuration Center (Versions > IDS Probe - Stop/Start).

Alert