Hi everybody,
I’m trying to tune my suricata configuration. Inspecting the log files produced by suricata I stumbled on segment_memcap_drop_delta
and reassembly_gap_delta
. I thought that increasing the reassembly memcap would fix my drop but i was wrong. Can anyone please explain me the difference between this two metrics?
Thanks,
Luca