Analysis of the rule_perf.log log file

Need help with rule profiling (11.9. Rule Profiling — Suricata 8.0.0-dev documentation). I did profiling, but I don’t understand how to use the resulting file.

It is very necessary to reduce the number of rules, because there are 70,000 of them.

I am attaching the file rule_perf.log
rule_perf.log (47.0 KB)

What are you missing? The documentation explains the different values. So you see which rules use the most of your CPU resources also based on matches or non-matches.