Update Suricata configuration. #14385
Replies: 5 comments 8 replies
-
There are other things you should tune first before needing to change buffer size: |
Beta Was this translation helpful? Give feedback.
-
Thank you for your reply and for the time you are dedicating to me. 🥇
Following the suricata documentation you indicated I set:
But it doesn't seem to have changed too much. |
Beta Was this translation helpful? Give feedback.
-
I can't find the Suricata tuning page in Security Onion.
Sure, but I do this filter as a switch.
From a span port.
Intel Xeon Gold 6226R |
Beta Was this translation helpful? Give feedback.
-
I have tried with various configurations and the result is always the same. I think the problem is elsewhere and in fact my network has a particularity that I don't think everyone has. |
Beta Was this translation helpful? Give feedback.
-
Some time has passed and I have done other tests, in particular the last one is very interesting to me. So I have no other ideas on how to proceed... |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
In the Sensor of my distributed system I have spikes of packets dropped by Suricata even if the CPU is very underutilized, it rarely goes beyond 40%, searching I found that it could be useful to increase the buffer-size in the Suricata configuration file (/opt/so/conf/suricata/suricata.yaml).
So I modified the file, bringing the value from 32768 to 2097152, and restarting the docker so-suricata:2.4.130.
But when I try to do it the change to the file is overwritten after a short time.
Can you tell me how to make this change permanently?
Can you tell me the correct way to change these settings?
Beta Was this translation helpful? Give feedback.
All reactions