# High traffic rulesets to use and wazuh configuration

**URL:** https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458
**Category:** Uncategorized
**Created:** [March 12, 2025, 10:54am UTC](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458 "2025-03-12T10:54:40Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Hamid\_Haitam](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/hamid_haitam/32/3485_2.png) [@Hamid\_Haitam](https://forum.suricata.io/u/Hamid_Haitam)
#### Post date: [March 12, 2025, 10:54am UTC](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458/1 "2025-03-12T10:54:41Z")

</div>

Hello Suricata Community,

I am currently using Suricata to monitor traffic from a 10GB TAP. I tested it with the default rules, and within just 30 minutes, the `eve.json` file grew to 5GB, generating 3 million hits in Wazuh. This caused a significant delay in the Wazuh dashboard, making it difficult to detect current alerts in real time.

What tweaks can I apply to optimize performance? Also, are there specific rules that I should disable to filter out less important alerts?

---

<div class="post-metadata">

### Author: ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)
#### Post date: [March 12, 2025, 12:03pm UTC](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458/2 "2025-03-12T12:03:05Z")

</div>

Please post your `suricata.yaml` so we can give you some hints what you can adjust from the log perspective.  
Also what ruleset you use exactly.  
It’s not very uncommon to have big log files, so most folks take care of that in post processing.

---

<div class="post-metadata">

### Author: ![Hamid\_Haitam](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/hamid_haitam/32/3485_2.png) [@Hamid\_Haitam](https://forum.suricata.io/u/Hamid_Haitam)
#### Post date: [March 12, 2025, 12:16pm UTC](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458/3 "2025-03-12T12:16:44Z")

</div>

Hello,  
I didn’t make many changes in the `suricata.yaml` file. I only specified the `AFPacket` interface, `HOME_NET`, and enabled the community ID.

As for the rules, I just used the default ones and didn’t change anything. That’s why I’m asking if I should remove some rules or specify only a group of important ones recommended by your team.

---

<div class="post-metadata">

### Author: ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)
#### Post date: [April 7, 2025, 8:23pm UTC](https://forum.suricata.io/t/high-traffic-rulesets-to-use-and-wazuh-configuration/5458/4 "2025-04-07T20:23:15Z")

</div>

What default set are you talking about? The ones we ship with `/rules` or the ETOpen ruleset?  
What rules trigger mostly that annoy you?
