IDS vs IPS
An intrusion detection system observes copied traffic and alerts. An intrusion prevention system sits inline on the data path and blocks. Snort and Suricata operate as either; Zeek (formerly Bro) is a flow-analysis engine that is detection-only.