# High computational load due to poor choice of fast\_pattern

**URL:** <https://forum.suricata.io/t/high-computational-load-due-to-poor-choice-of-fast-pattern/6342>\
**Category:** Rules\
**Tags:** rules\
**Created:** [May 23, 2026, 10:22pm UTC](https://forum.suricata.io/t/high-computational-load-due-to-poor-choice-of-fast-pattern/6342 "2026-05-23T22:22:55Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![user555](https://avatars.discourse-cdn.com/v4/letter/u/8c91f0/32.png) [@user555](https://forum.suricata.io/u/user555)\
**Post date:** [May 23, 2026, 10:22pm UTC](https://forum.suricata.io/t/high-computational-load-due-to-poor-choice-of-fast-pattern/6342/1 "2026-05-23T22:22:55Z")

</div>

Hello, dear colleagues. While researching suricata rules profiling, I encountered a question that I cannot clarify without your experience and knowledge.  
Only one rule is loaded.  
`alert tcp any any <> any any (flow:established; content:“Q”; fast_pattern; content:“AAAAAA”; sid:1;)`

Using netcat, I transfer a txt file with the contents QQQQQQQQQQAAAAAAQQQQQQQQQQQ.  
I receive the following profiling data.

[rule\_perf.log](https://forum.suricata.io/uploads/short-url/xMmP67QvlmRXBLSeeUCo4sFEtBV.log) (4.1 KB)

My question is: what causes such a high number of checks? Is it the MPM mechanism? Then why are there so few matches? How does it work? Please explain. Thank you.
