Suricata is known as a high-performance signature-based open source IDS/IPS. As with all signature based IDS, it produces millions of security events that are difficult to sort through. This talk will show how it is possible to leverage contextual metadata and a thread-based approach to get IDS alive and useful.