Created by Sourcefire, Unified2 is a IDS event file format from which programs such as Barnyard2 parse said events to other known and recognizable formats (Snort, MySQL, syslog, etc.).

Suricata writes only in Unified2 format, and Sourcefire has announced that the upcoming Snort release 2.9.3 will only write in Unified2, as the current version writes in Unified2 or to a database.

Unified2 offers IPv6 support.