# ERRCODE: SC\_ERR\_INVALID\_VALUE(130)\] - Failed to compile BPF

**URL:** <https://forum.suricata.io/t/errcode-sc-err-invalid-value-130-failed-to-compile-bpf/1341>\
**Category:** Help\
**Tags:** community\
**Created:** [May 4, 2021, 10:23am UTC](https://forum.suricata.io/t/errcode-sc-err-invalid-value-130-failed-to-compile-bpf/1341 "2021-05-04T10:23:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Binu\_Paul](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/binu_paul/32/761_2.png) [@Binu\_Paul](https://forum.suricata.io/u/Binu_Paul)\
**Post date:** [May 4, 2021, 10:23am UTC](https://forum.suricata.io/t/errcode-sc-err-invalid-value-130-failed-to-compile-bpf/1341/1 "2021-05-04T10:23:56Z")

</div>

Hi,  
i am using suricata-5.0.4 version with pf\_ring , when i increase the thread in suricata.yaml file and start suricata i am getting below error

4/5/2021 – 09:54:23 - - [ERRCODE: SC\_ERR\_INVALID\_VALUE(130)] - Failed to compile BPF “\>\> /var/log/ez-suricata-run.log 2\>&1”  
4/5/2021 – 09:54:23 - - [ERRCODE: SC\_ERR\_INVALID\_VALUE(130)] - Failed to compile BPF “\>\> /var/log/ez-suricata-run.log 2\>&1”  
4/5/2021 – 09:54:23 - - [ERRCODE: SC\_ERR\_INVALID\_VALUE(130)] - Failed to compile BPF “\>\> /var/log/ez-suricata-run.log 2\>&1”  
4/5/2021 – 09:54:23 - - [ERRCODE: SC\_ERR\_INVALID\_VALUE(130)] - Failed to compile BPF “\>\> /var/log/ez-suricata-run.log 2\>&1”  
4/5/2021 – 09:54:23 - - [ERRCODE: SC\_ERR\_INVALID\_VALUE(130)] - Failed to compile BPF “\>\> /var/log/ez-suricata-run.log 2\>&1”  
4/5/2021 – 09:54:23 - - [ERRCODE: SC\_ERR\_INVALID\_VALUE(130)] - Failed to compile BPF “\>\> /var/log/ez-suricata-run.log 2\>&1”

suricata.yaml

pfring:

- interface: eth0  
threads: 8  
cluster-id: 88  
cluster-type: cluster\_flow

my service file  
/usr/bin/suricata --pfring-int=eth0 --pfring-cluster-id=88 --pfring-cluster-type=cluster\_flow -c /opt/etc/suricata/suricata.yaml

Linux version  
Static hostname: \<\>  
Icon name: computer-server  
Chassis: server  
Machine ID: \<\>  
Boot ID: \<\>  
Operating System: Ubuntu 18.04.5 LTS  
Kernel: Linux 5.4.0-72-generic  
Architecture: x86-64

---

<div class="post-metadata">

**Author:** ![Jeff\_Lucovsky](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jeff_lucovsky/32/11_2.png) [@Jeff\_Lucovsky](https://forum.suricata.io/u/Jeff_Lucovsky)\
**Post date:** [May 4, 2021, 12:53pm UTC](https://forum.suricata.io/t/errcode-sc-err-invalid-value-130-failed-to-compile-bpf/1341/2 "2021-05-04T12:53:37Z")

</div>

Can you post the PF Ring configuration section from your suricata.yaml file?

For reference only, here’s the default `pfring` configuration for Suricata 7-ish:

```auto
# PF_RING configuration: for use with native PF_RING support
# for more info see http://www.ntop.org/products/pf_ring/
pfring:
  - interface: eth0
    # Number of receive threads. If set to 'auto' Suricata will first try
    # to use CPU (core) count and otherwise RSS queue count.
    threads: auto

    # Default clusterid. PF_RING will load balance packets based on flow.
    # All threads/processes that will participate need to have the same
    # clusterid.
    cluster-id: 99

    # Default PF_RING cluster type. PF_RING can load balance per flow.
    # Possible values are cluster_flow or cluster_round_robin.
    cluster-type: cluster_flow

    # bpf filter for this interface
    #bpf-filter: tcp

    # If bypass is set then the PF_RING hw bypass is activated, when supported
    # by the network interface. Suricata will instruct the interface to bypass
    # all future packets for a flow that need to be bypassed.
    #bypass: yes

    # Choose checksum verification mode for the interface. At the moment
    # of the capture, some packets may have an invalid checksum due to
    # the checksum computation being offloaded to the network card.
    # Possible values are:
    # - rxonly: only compute checksum for packets received by network card.
    # - yes: checksum validation is forced
    # - no: checksum validation is disabled
    # - auto: Suricata uses a statistical approach to detect when
    # checksum off-loading is used. (default)
    # Warning: 'checksum-validation' must be set to yes to have any validation
    #checksum-checks: auto
  # Second interface
  #- interface: eth1
  # threads: 3
  # cluster-id: 93
  # cluster-type: cluster_flow
  # Put default values here
  - interface: default
    #threads: 2

```
