Suricata drop #14635
Unanswered
pawsitivtyBE
asked this question in
2.4
Suricata drop
#14635
Replies: 1 comment 3 replies
-
How are your CPUs pinned? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.141
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
airgap
Hardware Specs
Exceeds minimum requirements
CPU
112
RAM
269
Storage for /
75Gb
Storage for /nsm
13Tb
Network Traffic Collection
tap
Network Traffic Speeds
1Gbps to 10Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
Hey,
I keep getting suricata loss (or drops?) with the low amount of 1.3Gbps traffic as you can see in screenshot.
I've already played around with the ring-size, threads, cpu-affinity and making sure the CPU workers are set to the NUMA node my NIC is connected to.
Any help on this would be appreciated. I've been searching for a few days now.
I use tcpreplay to send a pcap file from a multitude of hosts, which are fiber tapped.
cpu-affinity: yes
worker-cpu: 2-56
max-pending packets: 65534
threads: 70
ring-size: 4096
Doing the TOP command, yes I can see CPU 100%+, but even when I got it at around 60% by adjusting the thread count I still got loss.
Kind regards,
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions