# High number of kernel\_drops

**URL:** https://forum.suricata.io/t/high-number-of-kernel-drops/520
**Category:** Help
**Created:** [August 19, 2020, 12:59pm UTC](https://forum.suricata.io/t/high-number-of-kernel-drops/520 "2020-08-19T12:59:50Z")
**Posts on this page:** 1
**Showing post:** 12

<div class="post-metadata">

### Author: ![Souji\_T](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/souji_t/32/2633_2.png) [@Souji\_T](https://forum.suricata.io/u/Souji_T)
#### Post date: [October 6, 2020, 2:04pm UTC](https://forum.suricata.io/t/high-number-of-kernel-drops/520/12 "2020-10-06T14:04:46Z")

</div>

Hi,  
in case you have not solved your problem, this helped me with a similar problem.

> [@Suricata high capture.kernel\_drops count](https://forum.suricata.io/t/suricata-high-capture-kernel-drops-count/465/24):
>
> At first, I want to thank everybody who helped me with this problem! If anybody should have a similar problem, here what we did: set cluster-type: to cluster\_flow set runmode: to workers activate and configure the cpu-affinity settings In the end what really did the trick I think, was setting mmap-locked: and tpacket-v3: to yes. But in order to use the mmap-locked option you have to edit the /etc/security/limits.conf file and add something like this to the End of the file, otherwise surica…

In short:  
I had to uncomment `mmap-locked` and `tpacket-v3` and also change some memory settings so that suricata was able to reserve enough memory.

---

_[View the full topic](https://forum.suricata.io/t/high-number-of-kernel-drops/520)._
