# Uncategorized

**URL:** https://forum.suricata.io/c/uncategorized/1.md?page=1

[Latest](https://forum.suricata.io/latest.md) · [Categories](https://forum.suricata.io/categories.md) · [Tags](https://forum.suricata.io/tags.md)

**Page:** 2

---

## [I have question about byte\_jump](https://forum.suricata.io/t/i-have-question-about-byte-jump/6009)

<div class="topic-metadata">

**Author:** [@trymp](https://forum.suricata.io/u/trymp)\
**Replies:** 1\
**Last updated:** [September 13, 2025, 2:25pm UTC](https://forum.suricata.io/t/i-have-question-about-byte-jump/6009 "2025-09-13T14:25:10Z")

</div>

Suricata 7.0.10 alert tcp any any → any 80 ( msg:“HTTP suspicious option length”; flow:to\_server,established; byte\_jump:1,0,bitmask 0x0F,relative; content:“evil”; within 10; ) this rule parse error. Is byte\_jump …

---

## [TLS-store enabled but no certificate data collected in folder /var/log/suricata/certs](https://forum.suricata.io/t/tls-store-enabled-but-no-certificate-data-collected-in-folder-var-log-suricata-certs/5987)

<div class="topic-metadata">

**Author:** [@alex\_49100](https://forum.suricata.io/u/alex_49100)\
**Replies:** 1\
**Last updated:** [September 9, 2025, 1:51pm UTC](https://forum.suricata.io/t/tls-store-enabled-but-no-certificate-data-collected-in-folder-var-log-suricata-certs/5987 "2025-09-09T13:51:37Z")

</div>

Hello to the Suricata community, Running : Suricata version 7.0.11 RELEASE installed from packages on Oracle Linux 9.6 and Debian 13 Topic: I would like to collect the certificate data via the tls store feature. The…

---

## [Suricata crashes in nfnetlink library](https://forum.suricata.io/t/suricata-crashes-in-nfnetlink-library/6005)

<div class="topic-metadata">

**Author:** [@gsrinivas](https://forum.suricata.io/u/gsrinivas)\
**Replies:** 0\
**Last updated:** [September 9, 2025, 4:02am UTC](https://forum.suricata.io/t/suricata-crashes-in-nfnetlink-library/6005 "2025-09-09T04:02:36Z")

</div>

Suricata crashing in nfnetlink library, when the system appears to be in idle state (gdb) bt #0 0x00007f07b3465222 in nfnl\_handle\_packet () from /lib/x86\_64-linux-gnu/libnfnetlink.so.0 #1 0x00000000006505ab in NFQRe…

---

## [10% capture.kernel\_drops](https://forum.suricata.io/t/10-capture-kernel-drops/5928)

<div class="topic-metadata">

**Author:** [@GrumpyLT](https://forum.suricata.io/u/GrumpyLT)\
**Replies:** 1\
**Last updated:** [August 28, 2025, 12:45pm UTC](https://forum.suricata.io/t/10-capture-kernel-drops/5928 "2025-08-28T12:45:06Z")

</div>

Feel free to point me in the right direction and tell me to RTFM, but I figured I might as well post on here before I go off into weeds. Here is the current state: Suricata version 8.0.0 running in IDS mode 10 gig Due…

---

## [Lua Redis Module Loading Failure in Suricata 8.0.0 DPDK Mode: socket.coreError undefined symbol: lua\_pcall](https://forum.suricata.io/t/lua-redis-module-loading-failure-in-suricata-8-0-0-dpdk-mode-socket-coreerror-undefined-symbol-lua-pcall/5975)

<div class="topic-metadata">

**Author:** [@helloworld2019](https://forum.suricata.io/u/helloworld2019)\
**Replies:** 1\
**Last updated:** [August 25, 2025, 8:26am UTC](https://forum.suricata.io/t/lua-redis-module-loading-failure-in-suricata-8-0-0-dpdk-mode-socket-coreerror-undefined-symbol-lua-pcall/5975 "2025-08-25T08:26:58Z")

</div>

Hello Suricata Community, I’m encountering a module-loading error when using a Lua script to interact with Redis in Suricata 8.0.0 (DPDK mode). The similar test script works flawlessly outside Suricata (e.g., via LuaJIT…

---

## [How to fix SURICATA Ethertype unknown](https://forum.suricata.io/t/how-to-fix-suricata-ethertype-unknown/5927)

<div class="topic-metadata">

**Author:** [@mrn](https://forum.suricata.io/u/mrn)\
**Replies:** 1\
**Last updated:** [August 17, 2025, 12:59pm UTC](https://forum.suricata.io/t/how-to-fix-suricata-ethertype-unknown/5927 "2025-08-17T12:59:47Z")

</div>

Hello, guys, from month ago I installed suricata for my network, and got this alert: 08/14/2025-14:55:44.377170 \[\] \[1:2200121:1\] SURICATA Ethertype unknown \[\] \[Classification: Generic Protocol Command Decode\] \[Priority…

---

## [Error with suricata-update under RHEL10](https://forum.suricata.io/t/error-with-suricata-update-under-rhel10/5887)

<div class="topic-metadata">

**Author:** [@clopmz](https://forum.suricata.io/u/clopmz)\
**Replies:** 8\
**Last updated:** [July 29, 2025, 9:25pm UTC](https://forum.suricata.io/t/error-with-suricata-update-under-rhel10/5887 "2025-07-29T21:25:48Z")

</div>

Hi all, suricata-update returns the following error under a RHEL10 host: root@surisrv01:/etc/suricata# suricata-update -c /etc/suricata/update/update.yaml 20/7/2025 – 09:51:20 - – Loading /etc/suricata/update/update.…

---

## [Some errors with Suricata 7.0.11 and RHEL10](https://forum.suricata.io/t/some-errors-with-suricata-7-0-11-and-rhel10/5886)

<div class="topic-metadata">

**Author:** [@clopmz](https://forum.suricata.io/u/clopmz)\
**Replies:** 1\
**Last updated:** [July 21, 2025, 3:40pm UTC](https://forum.suricata.io/t/some-errors-with-suricata-7-0-11-and-rhel10/5886 "2025-07-21T15:40:42Z")

</div>

Good morning, I have installed Suricata 7.0.11 under a RHEL10 host (fully updated) and I am receiving errors regarding to use af-packet with XDP driver. First, Suricata build info: This is Suricata version 7.0.11 RELE…

---

## [Request for Enhanced Rule Management Interface in Suricata](https://forum.suricata.io/t/request-for-enhanced-rule-management-interface-in-suricata/5867)

<div class="topic-metadata">

**Author:** [@Georg\_Schwaiger](https://forum.suricata.io/u/Georg_Schwaiger)\
**Replies:** 2\
**Last updated:** [July 18, 2025, 6:06am UTC](https://forum.suricata.io/t/request-for-enhanced-rule-management-interface-in-suricata/5867 "2025-07-18T06:06:28Z")

</div>

Dear Suricata Team, I am reaching out with an urgent request from real-world practice. The current rule management in Suricata (e.g., as integrated in OPNsense) is barely usable for administrators in day-to-day operati…

---

## [Suricata-7 crashed while processing a packet, even before Initialisation](https://forum.suricata.io/t/suricata-7-crashed-while-processing-a-packet-even-before-initialisation/5869)

<div class="topic-metadata">

**Author:** [@gsrinivas](https://forum.suricata.io/u/gsrinivas)\
**Replies:** 2\
**Last updated:** [July 18, 2025, 4:49am UTC](https://forum.suricata.io/t/suricata-7-crashed-while-processing-a-packet-even-before-initialisation/5869 "2025-07-18T04:49:54Z")

</div>

I am running Suricata-7 in NFQ mode It crashed during Init Program terminated with signal SIGSEGV, Segmentation fault. #0 0x00000000005b859e in StatsIncr (tv=tv@entry=0x6988280, id=) at counters.c:181 \[Current thread…

---

## [Suricata 7.0.7 af-packet IPS mode slow down internet web browsing](https://forum.suricata.io/t/suricata-7-0-7-af-packet-ips-mode-slow-down-internet-web-browsing/5631)

<div class="topic-metadata">

**Author:** [@Vincent](https://forum.suricata.io/u/Vincent)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 9:05pm UTC](https://forum.suricata.io/t/suricata-7-0-7-af-packet-ips-mode-slow-down-internet-web-browsing/5631 "2025-07-17T21:05:55Z")

</div>

Hi, I am running suricata 7.0.7 in open source firewall IPFire in af-packet IPS mode, when client from IPFire green network browse Internet, it takes more than at least 1 minute to load the web page, or load youtube vi…

---

## [When Suricata 7.0.10 outputs alert logs in eve.json, how can one know which part of the packet's keyword was matched by the rule?](https://forum.suricata.io/t/when-suricata-7-0-10-outputs-alert-logs-in-eve-json-how-can-one-know-which-part-of-the-packets-keyword-was-matched-by-the-rule/5652)

<div class="topic-metadata">

**Author:** [@Edison\_Chen](https://forum.suricata.io/u/Edison_Chen)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 9:03pm UTC](https://forum.suricata.io/t/when-suricata-7-0-10-outputs-alert-logs-in-eve-json-how-can-one-know-which-part-of-the-packets-keyword-was-matched-by-the-rule/5652 "2025-07-17T21:03:20Z")

</div>

When Suricata 7.0.9 outputs alert logs in eve.json, how can one know which part of the packet’s keyword was matched by the rule?

---

## [Syslog output (please stop requiring a certain amount of characters for a subject thanks)](https://forum.suricata.io/t/syslog-output-please-stop-requiring-a-certain-amount-of-characters-for-a-subject-thanks/5872)

<div class="topic-metadata">

**Author:** [@DigiAngel](https://forum.suricata.io/u/DigiAngel)\
**Replies:** 2\
**Last updated:** [July 15, 2025, 4:37pm UTC](https://forum.suricata.io/t/syslog-output-please-stop-requiring-a-certain-amount-of-characters-for-a-subject-thanks/5872 "2025-07-15T16:37:36Z")

</div>

Per the 8.0.0 install: 15/7/2025 -- 10:29:24 - \<Warning\> -- The syslog output has been deprecated and will be removed in Suricata 9.0. Please don’t do this. This is one of the best ways to archive alert info.

---

## [Suricata Rule : allowed to use variables in content?](https://forum.suricata.io/t/suricata-rule-allowed-to-use-variables-in-content/5845)

<div class="topic-metadata">

**Author:** [@k4nfr3](https://forum.suricata.io/u/k4nfr3)\
**Replies:** 2\
**Last updated:** [July 11, 2025, 6:44am UTC](https://forum.suricata.io/t/suricata-rule-allowed-to-use-variables-in-content/5845 "2025-07-11T06:44:06Z")

</div>

Hi, content:!“|C0 A8 01 01|”; # This works content:!$DHCP\_SERVERS; # This fails to parse I’m trying to detect rogue DHCP servers, and want to detect option54 values instead of src or dst ip addresses Any suggesti…

---

## [Recommendations for sizing nf\_queue](https://forum.suricata.io/t/recommendations-for-sizing-nf-queue/5784)

<div class="topic-metadata">

**Author:** [@jimoe](https://forum.suricata.io/u/jimoe)\
**Replies:** 6\
**Last updated:** [July 1, 2025, 8:12pm UTC](https://forum.suricata.io/t/recommendations-for-sizing-nf-queue/5784 "2025-07-01T20:12:28Z")

</div>

Suricata version 7.0.10 RELEASE opensuse LEAP 15.6 linux 6.4.0 Today when inspecting the system log, a large number of these entries were present: 2025-06-17T09:31:14-0700 sma-server3 kernel: net\_ratelimit: 24 callba…

---

## [Desactivating stats log in eve-logs](https://forum.suricata.io/t/desactivating-stats-log-in-eve-logs/5777)

<div class="topic-metadata">

**Author:** [@SylvainB](https://forum.suricata.io/u/SylvainB)\
**Replies:** 2\
**Last updated:** [June 16, 2025, 11:50am UTC](https://forum.suricata.io/t/desactivating-stats-log-in-eve-logs/5777 "2025-06-16T11:50:23Z")

</div>

Hello, I just finish my first installation of Suricata, on a redhat server (via DNF installation) I need to send the suricata eve log to my siem, but to avoid to much log I don’t want the stats log in the eve.json file…

---

## [Af-packet w tpacket-v3 vs af-packet without](https://forum.suricata.io/t/af-packet-w-tpacket-v3-vs-af-packet-without/5741)

<div class="topic-metadata">

**Author:** [@DigiAngel](https://forum.suricata.io/u/DigiAngel)\
**Replies:** 2\
**Last updated:** [June 4, 2025, 5:57pm UTC](https://forum.suricata.io/t/af-packet-w-tpacket-v3-vs-af-packet-without/5741 "2025-06-04T17:57:07Z")

</div>

Is there a HUGE benefit to enabling tpacket-v3 in non-inline mode? Or is it minor? Thank you.

---

## [Netflow collector](https://forum.suricata.io/t/netflow-collector/5718)

<div class="topic-metadata">

**Author:** [@Raphael\_Rodrigues](https://forum.suricata.io/u/Raphael_Rodrigues)\
**Replies:** 1\
**Last updated:** [May 27, 2025, 1:51pm UTC](https://forum.suricata.io/t/netflow-collector/5718 "2025-05-27T13:51:52Z")

</div>

Hi. Even compiling with the --enable-netflow parameter, suricata does not provide the functionality - suricata --build-info | grep netflow. Is this a bug? Doesn’t suricata have integration with netflow data exported by…

---

## [Error updating on Alma 9](https://forum.suricata.io/t/error-updating-on-alma-9/5684)

<div class="topic-metadata">

**Author:** [@Luca\_vb](https://forum.suricata.io/u/Luca_vb)\
**Replies:** 4\
**Last updated:** [May 16, 2025, 1:13am UTC](https://forum.suricata.io/t/error-updating-on-alma-9/5684 "2025-05-16T01:13:40Z")

</div>

Hello, Dnf update gives me these errors, would appreciate some guidance on how to fix: Error: Problem: cannot install the best update candidate for package suricata-1:7.0.10-1.el9.x86\_64 nothing provides librte\_ea…

---

## [DPDK Mode - Support for L3 In-Line Configuration (iptables/nftables equivalent)](https://forum.suricata.io/t/dpdk-mode-support-for-l3-in-line-configuration-iptables-nftables-equivalent/5630)

<div class="topic-metadata">

**Author:** [@infinitydon](https://forum.suricata.io/u/infinitydon)\
**Replies:** 1\
**Last updated:** [May 12, 2025, 9:06am UTC](https://forum.suricata.io/t/dpdk-mode-support-for-l3-in-line-configuration-iptables-nftables-equivalent/5630 "2025-05-12T09:06:51Z")

</div>

Hi everyone, I’m currently exploring Suricata in DPDK mode and wanted to ask whether it supports Layer 3 in-line configurations similar to what is described in the documentation for standard Linux deployments using ipta…

---

## [Suricata support breakout mode?](https://forum.suricata.io/t/suricata-support-breakout-mode/5626)

<div class="topic-metadata">

**Author:** [@hj5232001](https://forum.suricata.io/u/hj5232001)\
**Replies:** 1\
**Last updated:** [April 20, 2025, 1:05pm UTC](https://forum.suricata.io/t/suricata-support-breakout-mode/5626 "2025-04-20T13:05:34Z")

</div>

I would like to confirm whether Suricata supports breakout mode for network interfaces? Kindly please help me. Thanks & Regards Tai tai@linkwen.com.tw

---

## [Capture file not always exsits for alerts (Suricata v.7 Conditional PCAP)](https://forum.suricata.io/t/capture-file-not-always-exsits-for-alerts-suricata-v-7-conditional-pcap/3443)

<div class="topic-metadata">

**Author:** [@Jackojack7](https://forum.suricata.io/u/Jackojack7)\
**Replies:** 5\
**Last updated:** [April 9, 2025, 1:32pm UTC](https://forum.suricata.io/t/capture-file-not-always-exsits-for-alerts-suricata-v-7-conditional-pcap/3443 "2025-04-09T13:32:45Z")

</div>

Hello, I am using the new feature Conditional PCAP on Suricata v.7. When I run Suricata with pcap-log enabled, conditional set to alerts and mode set to multi - Suricata indeed logs the alerts to PCAP file but some of …

---

## [I have some questions about suricata](https://forum.suricata.io/t/i-have-some-questions-about-suricata/5562)

<div class="topic-metadata">

**Author:** [@Edison\_Chen](https://forum.suricata.io/u/Edison_Chen)\
**Replies:** 7\
**Last updated:** [April 9, 2025, 11:41am UTC](https://forum.suricata.io/t/i-have-some-questions-about-suricata/5562 "2025-04-09T11:41:29Z")

</div>

Question 1: How to dynamically update the rules in suricata? I want to conduct unified management of the rules through Java, which involves the operation of adding, deleting and modifying. How to synchronize the operatio…

---

## [Suricata 7.0.10 After unix-socket is Enabled, Logs cannot be output to eve.json. How can I Output logs to eve.json at the same time or Transmit Logs through unix-socket](https://forum.suricata.io/t/suricata-7-0-10-after-unix-socket-is-enabled-logs-cannot-be-output-to-eve-json-how-can-i-output-logs-to-eve-json-at-the-same-time-or-transmit-logs-through-unix-socket/5576)

<div class="topic-metadata">

**Author:** [@Edison\_Chen](https://forum.suricata.io/u/Edison_Chen)\
**Replies:** 1\
**Last updated:** [April 7, 2025, 8:37pm UTC](https://forum.suricata.io/t/suricata-7-0-10-after-unix-socket-is-enabled-logs-cannot-be-output-to-eve-json-how-can-i-output-logs-to-eve-json-at-the-same-time-or-transmit-logs-through-unix-socket/5576 "2025-04-07T20:37:08Z")

</div>

suricata 7.0.10 After unix-socket is Enabled, Logs cannot be output to eve.json. How can I Output logs to eve.json at the same time or Transmit Logs through unix-socket When running this command, eve.json does not outpu…

---

## [High traffic rulesets to use and wazuh configuration](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458)

<div class="topic-metadata">

**Author:** [@Hamid\_Haitam](https://forum.suricata.io/u/Hamid_Haitam)\
**Replies:** 3\
**Last updated:** [April 7, 2025, 8:23pm UTC](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458 "2025-04-07T20:23:15Z")

</div>

Hello Suricata Community, I am currently using Suricata to monitor traffic from a 10GB TAP. I tested it with the default rules, and within just 30 minutes, the eve.json file grew to 5GB, generating 3 million hits in Waz…

---

## [Suricata 7.0.10 cannot enable the unix-socket configuration](https://forum.suricata.io/t/suricata-7-0-10-cannot-enable-the-unix-socket-configuration/5573)

<div class="topic-metadata">

**Author:** [@Edison\_Chen](https://forum.suricata.io/u/Edison_Chen)\
**Replies:** 5\
**Last updated:** [April 2, 2025, 2:28am UTC](https://forum.suricata.io/t/suricata-7-0-10-cannot-enable-the-unix-socket-configuration/5573 "2025-04-02T02:28:02Z")

</div>

suricata.log (1.9 KB) suricata.yaml (85.1 KB) Here are my relevant configurations. Suricata does not output the log information of unix-command. Test the echo ‘{“command”: “help”}’ | nc -U /run/suricata/suricata-comma…

---

## [Interface ok, eve.json ok porem da erro no log wazuh](https://forum.suricata.io/t/interface-ok-eve-json-ok-porem-da-erro-no-log-wazuh/5538)

<div class="topic-metadata">

**Author:** [@admseg\_senff](https://forum.suricata.io/u/admseg_senff)\
**Replies:** 2\
**Last updated:** [March 31, 2025, 12:49pm UTC](https://forum.suricata.io/t/interface-ok-eve-json-ok-porem-da-erro-no-log-wazuh/5538 "2025-03-31T12:49:10Z")

</div>

Sou novo no cenário integração wazuh +suricata Estou com interface apontada porem nao consigo ainda comunicar com wazuh. Checando o log de eventos eve.json consigo ver captura de pacotes. fiz alteração no suricata.yam…

---

## [Suricata version7.0.9 failed to enable the bpf filter in af\_packet mode](https://forum.suricata.io/t/suricata-version7-0-9-failed-to-enable-the-bpf-filter-in-af-packet-mode/5560)

<div class="topic-metadata">

**Author:** [@Edison\_Chen](https://forum.suricata.io/u/Edison_Chen)\
**Replies:** 5\
**Last updated:** [March 31, 2025, 6:14am UTC](https://forum.suricata.io/t/suricata-version7-0-9-failed-to-enable-the-bpf-filter-in-af-packet-mode/5560 "2025-03-31T06:14:17Z")

</div>

error message i: suricata: This is Suricata version 7.0.9 RELEASE running in SYSTEM mode W: af-packet: ens33: AF\_PACKET tpacket-v3 is recommended for non-inline operation W: suricata: setrlimit has no effet whe…

---

## [Need help on Design of multiple instances of Suricata](https://forum.suricata.io/t/need-help-on-design-of-multiple-instances-of-suricata/5526)

<div class="topic-metadata">

**Author:** [@yogeshdp](https://forum.suricata.io/u/yogeshdp)\
**Replies:** 4\
**Last updated:** [March 28, 2025, 6:46pm UTC](https://forum.suricata.io/t/need-help-on-design-of-multiple-instances-of-suricata/5526 "2025-03-28T18:46:22Z")

</div>

I have 10 suricata machines as Internal NIDS. We need to reinstall those as base RHEL is supposed to upgrade to RHEL9 We also plan to push these machines to External network (passive mode / packer sniffing mode) and upd…

---

## [In 7.0.9 missing libpcre2-8-devel](https://forum.suricata.io/t/in-7-0-9-missing-libpcre2-8-devel/5501)

<div class="topic-metadata">

**Author:** [@jimoe](https://forum.suricata.io/u/jimoe)\
**Replies:** 6\
**Last updated:** [March 24, 2025, 5:55pm UTC](https://forum.suricata.io/t/in-7-0-9-missing-libpcre2-8-devel/5501 "2025-03-24T17:55:48Z")

</div>

openSUSE tumbleweed 20250313 Linux 6.13.6-1-default x86\_64 I unpacked Suricata 7.0.9 and ran configure as usual. $ ./configure --enable-nfqueue ... bunch o' success ... checking for pcre2\_compile\_8 in -lpcre2-8... n…

[Previous page](https://forum.suricata.io/c/uncategorized/1.md)

[Next page](https://forum.suricata.io/c/uncategorized/1.md?page=2)
