Driven by the need for a greater autonomy in detecting malicious activity at Brazilian academic networks, CAIS/RNP, the Brazilian National Academic and Research Network CSIRT - who serves to a constituency of approximately 600 institutions - developed its own monitoring solution based on an open source Network IDS/IPS (Suricata) using a master-engine model and incorporating additional features and customizations in order to obtain an efficient, easily-managed and complete solution for proactive detection of network security incidents, thus facilitating the day-to-day of incident handlers and strengthening the CSIRT incident handling capability, which is one of the core services of any CSIRT. This presentation aims to provide details on the implemented solution and challenges, and mainly to share this initiative with FIRST community in order to benefit other CSIRTs.