Drop stats explanation

Hi everybody,

I’m trying to tune my suricata configuration. Inspecting the log files produced by suricata I stumbled on segment_memcap_drop_delta and reassembly_gap_delta. I thought that increasing the reassembly memcap would fix my drop but i was wrong. Can anyone please explain me the difference between this two metrics?



What version are you running? There was a bug that lead to high memory usage.

The first one tells you that due to reaching the memcap limit parts are droped.

The other is that there is a gap within a stream when it was reassembled.