# Help

**URL:** https://forum.suricata.io/c/help/5.md?page=2

[Latest](https://forum.suricata.io/latest.md) · [Categories](https://forum.suricata.io/categories.md) · [Tags](https://forum.suricata.io/tags.md)

**Page:** 3

---

## [Throughput drop on Netgate 8200 MAX LAN/VLAN (ix1) with Suricata inline mode](https://forum.suricata.io/t/throughput-drop-on-netgate-8200-max-lan-vlan-ix1-with-suricata-inline-mode/6060)

<div class="topic-metadata">

**Author:** [@smsigroupit](https://forum.suricata.io/u/smsigroupit)\
**Replies:** 5\
**Last updated:** [October 15, 2025, 10:41pm UTC](https://forum.suricata.io/t/throughput-drop-on-netgate-8200-max-lan-vlan-ix1-with-suricata-inline-mode/6060 "2025-10-15T22:41:30Z")

</div>

Good day! Device: Netgate 8200 MAX Interface: LAN/VLAN (ix1) With Suricata in inline mode, throughput falls from ~1 Gbps to ~300 Mbps. With Suricata in legacy mode, throughput remains ~1 Gbps. What might be causing …

---

## [Large number of events with /libhtp::request\_uri\_not\_seen](https://forum.suricata.io/t/large-number-of-events-with-libhtp-request-uri-not-seen/6042)

<div class="topic-metadata">

**Author:** [@dachoa1005](https://forum.suricata.io/u/dachoa1005)\
**Replies:** 4\
**Last updated:** [October 4, 2025, 6:44am UTC](https://forum.suricata.io/t/large-number-of-events-with-libhtp-request-uri-not-seen/6042 "2025-10-04T06:44:40Z")

</div>

Environment: Debian 11 Suricata 6.0.14 running with af-packet mode Traffic: 500-600 Mbps on 2 interfaces (mostly HTTP traffic on port 80) How I installed Suricata: build from source using commands: +) bash scripts/b…

---

## [Rule updating broken? after upgrade from 7.0.9 to 7.0.11 (suricata-update 1.3.4 to 1.3.6)](https://forum.suricata.io/t/rule-updating-broken-after-upgrade-from-7-0-9-to-7-0-11-suricata-update-1-3-4-to-1-3-6/6026)

<div class="topic-metadata">

**Author:** [@duckasylum](https://forum.suricata.io/u/duckasylum)\
**Replies:** 4\
**Last updated:** [September 30, 2025, 3:42am UTC](https://forum.suricata.io/t/rule-updating-broken-after-upgrade-from-7-0-9-to-7-0-11-suricata-update-1-3-4-to-1-3-6/6026 "2025-09-30T03:42:16Z")

</div>

I am running Suricata version 7.0.9 on RHEL 9.4 installed from a self-.packaged rpm (I am following the “official” spec file). Now when I upgrade to 7.0.11 the upgrade script is unable to parse the regexes in the enable.…

---

## [Suricata not detecting anything?](https://forum.suricata.io/t/suricata-not-detecting-anything/6032)

<div class="topic-metadata">

**Author:** [@jimoe](https://forum.suricata.io/u/jimoe)\
**Replies:** 10\
**Last updated:** [September 29, 2025, 2:25pm UTC](https://forum.suricata.io/t/suricata-not-detecting-anything/6032 "2025-09-29T14:25:41Z")

</div>

Suricata 8.0.1 opensuse tumbleweed 0250918 linux v6.16.7-1-default x86\_64 Installation: make, make install AMD Ryzen 5 5600X × 12 32 GB RAM The suricata installation on this host has never been vary active. It was …

---

## [Granular logging of alerts and its meta data](https://forum.suricata.io/t/granular-logging-of-alerts-and-its-meta-data/6037)

<div class="topic-metadata">

**Author:** [@garil](https://forum.suricata.io/u/garil)\
**Replies:** 0\
**Last updated:** [September 29, 2025, 9:46am UTC](https://forum.suricata.io/t/granular-logging-of-alerts-and-its-meta-data/6037 "2025-09-29T09:46:03Z")

</div>

Please include the following information with your help request: Suricata version Operating system and/or Linux distribution How you installed Suricata (from source, packages, something else) Hello, Running Suricat…

---

## [Unable to run Suricata in IPS Mode](https://forum.suricata.io/t/unable-to-run-suricata-in-ips-mode/4959)

<div class="topic-metadata">

**Author:** [@newsuricatauser01](https://forum.suricata.io/u/newsuricatauser01)\
**Replies:** 3\
**Last updated:** [September 26, 2025, 6:30pm UTC](https://forum.suricata.io/t/unable-to-run-suricata-in-ips-mode/4959 "2025-09-26T18:30:26Z")

</div>

Hello, I am a new user of Suricata. I have managed to install and run Suricata in system mode (which I understood is IDS) but unable to run it in IPS mode. Would anybody help look at what is wrong please? Here are the…

---

## [How to Update suricata in Windows by commands](https://forum.suricata.io/t/how-to-update-suricata-in-windows-by-commands/6036)

<div class="topic-metadata">

**Author:** [@Ahnaf\_Tahmeed](https://forum.suricata.io/u/Ahnaf_Tahmeed)\
**Replies:** 2\
**Last updated:** [September 26, 2025, 1:55pm UTC](https://forum.suricata.io/t/how-to-update-suricata-in-windows-by-commands/6036 "2025-09-26T13:55:28Z")

</div>

Please include the following information with your help request: Suricata version Suricata version 7.0.7 Operating system is Windows Installed Suricata by Msi package

---

## [Basic Question regarding logging](https://forum.suricata.io/t/basic-question-regarding-logging/6027)

<div class="topic-metadata">

**Author:** [@topsirloin](https://forum.suricata.io/u/topsirloin)\
**Replies:** 2\
**Last updated:** [September 19, 2025, 12:44am UTC](https://forum.suricata.io/t/basic-question-regarding-logging/6027 "2025-09-19T00:44:19Z")

</div>

Please include the following information with your help request: Suricata version Operating system and/or Linux distribution How you installed Suricata (from source, packages, something else) I have just installed S…

---

## [Error Of Loading the Dataset in my rule file](https://forum.suricata.io/t/error-of-loading-the-dataset-in-my-rule-file/6024)

<div class="topic-metadata">

**Author:** [@Nij\_PADARIYA](https://forum.suricata.io/u/Nij_PADARIYA)\
**Replies:** 0\
**Last updated:** [September 18, 2025, 12:42pm UTC](https://forum.suricata.io/t/error-of-loading-the-dataset-in-my-rule-file/6024 "2025-09-18T12:42:43Z")

</div>

Suricata latest version using This is part of my Suricata.yaml file datasets: allow-absolute-filenames: true # Default fallback memcap and hashsize values for datasets in case these # were not explicitly defined.…

---

## [Running the af-packet quickstart example in the inline nfqueue mode](https://forum.suricata.io/t/running-the-af-packet-quickstart-example-in-the-inline-nfqueue-mode/5970)

<div class="topic-metadata">

**Author:** [@Oscar\_Wilde](https://forum.suricata.io/u/Oscar_Wilde)\
**Replies:** 3\
**Last updated:** [September 5, 2025, 11:19am UTC](https://forum.suricata.io/t/running-the-af-packet-quickstart-example-in-the-inline-nfqueue-mode/5970 "2025-09-05T11:19:44Z")

</div>

Hello, I’m trying to run nfqueue IPS mode, running the quickstart example (I’m modifying the example in the following section I’ll mention): sudo apt-get install software-properties-common sudo add-apt-repository ppa:o…

---

## [Suricata 8.0 non-root by default](https://forum.suricata.io/t/suricata-8-0-non-root-by-default/5946)

<div class="topic-metadata">

**Author:** [@evolution536](https://forum.suricata.io/u/evolution536)\
**Replies:** 5\
**Last updated:** [September 4, 2025, 11:03pm UTC](https://forum.suricata.io/t/suricata-8-0-non-root-by-default/5946 "2025-09-04T23:03:26Z")

</div>

Hello, I have had a setup with Suricata 7.x which was installed from the PPA in Ubuntu. This version of Suricata ran as root by default, and I have built a toolchain around Suricata. Suricata 8.0 has been released, whi…

---

## [Append variable to alert msg](https://forum.suricata.io/t/append-variable-to-alert-msg/5917)

<div class="topic-metadata">

**Author:** [@cs.lev](https://forum.suricata.io/u/cs.lev)\
**Replies:** 1\
**Last updated:** [August 23, 2025, 9:00pm UTC](https://forum.suricata.io/t/append-variable-to-alert-msg/5917 "2025-08-23T21:00:54Z")

</div>

Hi, I am playing around with Suricata v8.0 and I want to capture all DNS NXDOMAIN responses and see what the requested domains were that ended up having NXDOMAIN responses. I managed to create a rule that work perfectly…

---

## [Suricata IPS mode not working with Windivert on Windows 11](https://forum.suricata.io/t/suricata-ips-mode-not-working-with-windivert-on-windows-11/5948)

<div class="topic-metadata">

**Author:** [@gtrrnr](https://forum.suricata.io/u/gtrrnr)\
**Replies:** 0\
**Last updated:** [August 19, 2025, 3:16am UTC](https://forum.suricata.io/t/suricata-ips-mode-not-working-with-windivert-on-windows-11/5948 "2025-08-19T03:16:31Z")

</div>

Please include the following information with your help request: Suricata version: Suricata 8.0.0 Operating system: Windows 11 How you installed Suricata: from package Hi everyone. Recently i tried to enable IPS mo…

---

## [Af-packet yaml reference](https://forum.suricata.io/t/af-packet-yaml-reference/5931)

<div class="topic-metadata">

**Author:** [@KylePeterDavies](https://forum.suricata.io/u/KylePeterDavies)\
**Replies:** 3\
**Last updated:** [August 18, 2025, 12:16pm UTC](https://forum.suricata.io/t/af-packet-yaml-reference/5931 "2025-08-18T12:16:23Z")

</div>

Hi Suricata! I am new to Suricata, and I am trying to find the YAML Reference for af-packet I would have expected to find the reference here: 12.1. Suricata.yaml — Suricata 8.0.1-dev documentation. However, I cannot seem…

---

## [Suricata 7.0.5 file\_data not matching keyword near end of HTTP response body](https://forum.suricata.io/t/suricata-7-0-5-file-data-not-matching-keyword-near-end-of-http-response-body/5934)

<div class="topic-metadata">

**Author:** [@abhishek\_sharma](https://forum.suricata.io/u/abhishek_sharma)\
**Replies:** 0\
**Last updated:** [August 17, 2025, 12:58pm UTC](https://forum.suricata.io/t/suricata-7-0-5-file-data-not-matching-keyword-near-end-of-http-response-body/5934 "2025-08-17T12:58:21Z")

</div>

Hello, I’m testing Suricata 7.0.5 and trying to block HTTP traffic based on a keyword inside the file body. I created this rule: drop http any any -\> any any (msg:"Block Doyle Hound book based on content match"; file\_d…

---

## [JA4 Fingerprinting with Suricata 8.0](https://forum.suricata.io/t/ja4-fingerprinting-with-suricata-8-0/5918)

<div class="topic-metadata">

**Author:** [@cs.lev](https://forum.suricata.io/u/cs.lev)\
**Replies:** 5\
**Last updated:** [August 14, 2025, 7:25am UTC](https://forum.suricata.io/t/ja4-fingerprinting-with-suricata-8-0/5918 "2025-08-14T07:25:27Z")

</div>

Hi, I am running Suricata 8.0 in a container using jasonish/suricata:8.0. I want to play around with ja4+ hashed, especially ja4 (for clients) and ja4s for servers. However, I only found instructions on the Suricata doc…

---

## [Layer 2 clear cache](https://forum.suricata.io/t/layer-2-clear-cache/5924)

<div class="topic-metadata">

**Author:** [@Fret](https://forum.suricata.io/u/Fret)\
**Replies:** 0\
**Last updated:** [August 10, 2025, 5:28pm UTC](https://forum.suricata.io/t/layer-2-clear-cache/5924 "2025-08-10T17:28:42Z")

</div>

Dear Suricata community, I am working on Debian 12 with Suricata 8.0 installed and compiled from source. I have a use case where I want to run Suricata in AF\_PACKET mode at Layer 2 (which is working fine). Due to arch…

---

## [Rate\_filter not suppressing repeated alerts](https://forum.suricata.io/t/rate-filter-not-suppressing-repeated-alerts/5900)

<div class="topic-metadata">

**Author:** [@rahulm](https://forum.suricata.io/u/rahulm)\
**Replies:** 0\
**Last updated:** [July 30, 2025, 11:58am UTC](https://forum.suricata.io/t/rate-filter-not-suppressing-repeated-alerts/5900 "2025-07-30T11:58:30Z")

</div>

Please include the following information with your help request: Suricata version - 7.0.10 Operating system and/or Linux distribution - Ubuntu 22.04.5 LTS We’re observing an issue in Suricata where the rate\_filte…

---

## [Unable to capture the complete packet in a single pass](https://forum.suricata.io/t/unable-to-capture-the-complete-packet-in-a-single-pass/5871)

<div class="topic-metadata">

**Author:** [@0verflow](https://forum.suricata.io/u/0verflow)\
**Replies:** 10\
**Last updated:** [July 28, 2025, 8:21pm UTC](https://forum.suricata.io/t/unable-to-capture-the-complete-packet-in-a-single-pass/5871 "2025-07-28T20:21:19Z")

</div>

Suricata version: 7.0.8 Operating system: Ubuntu 20.04.6 LTS How to installed Suricata: packages When Suricata is configured with pcap-log to save packets that trigger alerts, only the HTTP request packet is recorde…

---

## [Building Suricata for Windows Without Npcap (Using MSYS2/libpcap and/or WinDivert)](https://forum.suricata.io/t/building-suricata-for-windows-without-npcap-using-msys2-libpcap-and-or-windivert/5895)

<div class="topic-metadata">

**Author:** [@Rossella\_Petrucci](https://forum.suricata.io/u/Rossella_Petrucci)\
**Replies:** 0\
**Last updated:** [July 28, 2025, 2:11pm UTC](https://forum.suricata.io/t/building-suricata-for-windows-without-npcap-using-msys2-libpcap-and-or-windivert/5895 "2025-07-28T14:11:26Z")

</div>

Hi everyone, We’re trying to install and run Suricata on Windows 11 without using NPCAP, because NPCAP now requires an OEM license for redistribution — which doesn’t fit our current use case. We had previously used ver…

---

## [Unable to enable additional rulesets, always defaults to Emerging Threats Open](https://forum.suricata.io/t/unable-to-enable-additional-rulesets-always-defaults-to-emerging-threats-open/5835)

<div class="topic-metadata">

**Author:** [@unknown](https://forum.suricata.io/u/unknown)\
**Replies:** 3\
**Last updated:** [July 23, 2025, 7:30pm UTC](https://forum.suricata.io/t/unable-to-enable-additional-rulesets-always-defaults-to-emerging-threats-open/5835 "2025-07-23T19:30:23Z")

</div>

Hello everyone! I am trying to enable an additional ruleset using suricata-update as described in the documentation. For instancse, following the official guide to enable the OISF TrafficID ruleset I am running the foll…

---

## [Suricata-update and disable/modify rule help](https://forum.suricata.io/t/suricata-update-and-disable-modify-rule-help/5880)

<div class="topic-metadata">

**Author:** [@atbohmer](https://forum.suricata.io/u/atbohmer)\
**Replies:** 1\
**Last updated:** [July 22, 2025, 2:12am UTC](https://forum.suricata.io/t/suricata-update-and-disable-modify-rule-help/5880 "2025-07-22T02:12:43Z")

</div>

Hello, Is it possible with suricata-update modify.conf/disable.conf to disable all ET/ETPRO rules with the following content: alert http $EXTERNAL\_NET any → $HOME\_NET any (msg:"ET SCAN More specific source is $EXTERNA…

---

## [Does the dpdk.eal-params.lcores use the same cores in worker-cpu-set?](https://forum.suricata.io/t/does-the-dpdk-eal-params-lcores-use-the-same-cores-in-worker-cpu-set/5885)

<div class="topic-metadata">

**Author:** [@dahaili](https://forum.suricata.io/u/dahaili)\
**Replies:** 1\
**Last updated:** [July 20, 2025, 3:19pm UTC](https://forum.suricata.io/t/does-the-dpdk-eal-params-lcores-use-the-same-cores-in-worker-cpu-set/5885 "2025-07-20T15:19:56Z")

</div>

Hi, This is coreset I configure in dpdk: dpdk: eal-params: proc-type: primary l: “32,34,36,38,40,42,44,46,48,50,52,54” And this is worker-cpu-set I configured: - worker-cpu-set: cpu: \[ 29,31,33,35,37,39,41,43,45,…

---

## [How to transfer the disabled rules list?](https://forum.suricata.io/t/how-to-transfer-the-disabled-rules-list/5608)

<div class="topic-metadata">

**Author:** [@emile](https://forum.suricata.io/u/emile)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 9:07pm UTC](https://forum.suricata.io/t/how-to-transfer-the-disabled-rules-list/5608 "2025-07-17T21:07:22Z")

</div>

Hello, I’m using SELKS 10. I’m looking for a means to transfer the Suricata disabled rules list from one machine to another. Anyone knows where they are stored?

---

## [Suricata IPS NFQ Inline Setup in Transparent Mode (Ubuntu)](https://forum.suricata.io/t/suricata-ips-nfq-inline-setup-in-transparent-mode-ubuntu/5726)

<div class="topic-metadata">

**Author:** [@Jasser\_Hach](https://forum.suricata.io/u/Jasser_Hach)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 8:56pm UTC](https://forum.suricata.io/t/suricata-ips-nfq-inline-setup-in-transparent-mode-ubuntu/5726 "2025-07-17T20:56:24Z")

</div>

Hi everyone, I’m setting up Suricata as an IPS using NFQUEUE in inline mode on Ubuntu, in transparent mode. Here’s my current setup: Modem\<==\> \[ens33|ens34|Suricata|ens32\]\<==\> LAN ens33 and ens32 have no IP addresse…

---

## [Surica dual network card packet loss issue](https://forum.suricata.io/t/surica-dual-network-card-packet-loss-issue/5670)

<div class="topic-metadata">

**Author:** [@mj2064662418](https://forum.suricata.io/u/mj2064662418)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 8:54pm UTC](https://forum.suricata.io/t/surica-dual-network-card-packet-loss-issue/5670 "2025-07-17T20:54:36Z")

</div>

Hey All: I use Surica 7.0.6 and ELK for traffic analysis. I have two network cards and use AF packet capture. My incoming and outgoing packets are not sent through the same network card, so I want to combine the two phy…

---

## [custom rules for port 20015](https://forum.suricata.io/t/custom-rules-for-port-20015/5765)

<div class="topic-metadata">

**Author:** [@lizardsquad](https://forum.suricata.io/u/lizardsquad)\
**Replies:** 2\
**Last updated:** [July 17, 2025, 8:52pm UTC](https://forum.suricata.io/t/custom-rules-for-port-20015/5765 "2025-07-17T20:52:44Z")

</div>

Hello, I’m using chatgpt to configure custom rules for port 20015. It suggested this rule, but it doesn’t work. Can anyone help me? drop tcp any any → any 20015 (msg:“BLOCK: TCP 20015 \> 40/s”; rate\_filter: track by\_s…

---

## [Suricata drops invalid TLS alerts and logs “SSL info incomplete” on HTTPS traffic](https://forum.suricata.io/t/suricata-drops-invalid-tls-alerts-and-logs-ssl-info-incomplete-on-https-traffic/5807)

<div class="topic-metadata">

**Author:** [@joved81744](https://forum.suricata.io/u/joved81744)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 8:44pm UTC](https://forum.suricata.io/t/suricata-drops-invalid-tls-alerts-and-logs-ssl-info-incomplete-on-https-traffic/5807 "2025-07-17T20:44:36Z")

</div>

Hi everyone, :waving\_hand: I am running Suricata 7.0.0 on Ubuntu 22.04 with TLS inspection enabled via a transparent proxy. However, I’m seeing frequent messages in the logs like: SSL event tls\_alert invalid status (wa…

---

## [Monitoring EKS hosts using suricata](https://forum.suricata.io/t/monitoring-eks-hosts-using-suricata/5846)

<div class="topic-metadata">

**Author:** [@Vinod\_Bele](https://forum.suricata.io/u/Vinod_Bele)\
**Replies:** 0\
**Last updated:** [July 7, 2025, 4:04pm UTC](https://forum.suricata.io/t/monitoring-eks-hosts-using-suricata/5846 "2025-07-07T16:04:55Z")

</div>

We’re using AWS VPC traffic mirroring to monitor EKS host traffic and send it to Suricata. Since EKS nodes have both a primary ENI (for host-level traffic) and multiple secondary ENIs (used by the AWS VPC CNI for pod tra…

---

## [How to use Suricata as an inline IPS between NGINX and backend pod in Kubernetes?](https://forum.suricata.io/t/how-to-use-suricata-as-an-inline-ips-between-nginx-and-backend-pod-in-kubernetes/5857)

<div class="topic-metadata">

**Author:** [@daniel](https://forum.suricata.io/u/daniel)\
**Replies:** 0\
**Last updated:** [July 9, 2025, 2:42pm UTC](https://forum.suricata.io/t/how-to-use-suricata-as-an-inline-ips-between-nginx-and-backend-pod-in-kubernetes/5857 "2025-07-09T14:42:39Z")

</div>

Hi everyone, I’m trying to set up suricata as an inline IPS in my k8s cluster to protect a web application running in a pod. Since incoming traffic is encrypted (https), I’m considering placing suricata between the ngi…

[Previous page](https://forum.suricata.io/c/help/5.md?page=1)

[Next page](https://forum.suricata.io/c/help/5.md?page=3)
