Best Ways to Use Suricata in a High Traffic Network Situation

Hi,

Suricata performance is a broad topic and much of it depends on your

  • Deployment – what type of traffic will it monitor?
  • Machine resources
    • CPU
    • Memory
    • Disk subsystem
    • Network interface card(s)
  • Deployment Mode – inline (IPS) or passive (IDS)
  • Suricata rule set

We’ve prepared information to provide general guidelines – 11. Performance — Suricata 8.0.0-dev documentation. The great @pevma and his colleagues have written and shared the “Suricata Extreme Performance Tuning Guide” (aka SEPTun).