Af_xdp suricata yaml

Hi everyone,

I want to start suricata af_xdp mode but I don’t know how to configure suricata.yaml. Can anyone share an example suricata.yaml to start af_xdp mode?

Best regards.

You can read more about that on 21.4. eBPF and XDP — Suricata 7.0.0-rc3-dev documentation and 21.6. AF_XDP — Suricata 7.0.0-rc3-dev documentation also the suricata.yaml shipped has the section with some comments.

To start it in that mode you need to pass --af-xdp when you run Suricata.


Can I use the xdp maps in order to early drop for specific packages which define in suricata.rules?
And is there any xdp program in suricata examples for do this?


You can see examples in