How to Address Performance Issues with Suricata 6.0.1?

Hello guys! :blush:

I am facing performance issues :pensive: with Suricata version 6.0.1 and I can use some guidance in troubleshooting and resolving them. I faced problem in these points:

  • Performance Degradation: Since upgrading to Suricata 6.0.1, I’ve noticed a significant degradation in performance compared to previous versions. Suricata seems to be consuming more CPU and memory resources, leading to slower network throughput and increased latency.

  • Configuration Review: I’ve reviewed my Suricata configuration to ensure that it aligns with recommended best practices, but I’m still experiencing performance issues. Are there any specific configuration options or settings in Suricata 6.0.1 that I should pay particular attention to in order to optimize performance?

  • Hardware Considerations: I’m also curious :smiley: if there are any hardware recommendations or considerations for running Suricata 6.0.1 optimally. Are there any known compatibility issues with certain hardware configurations that could be contributing to the performance issues?

  • Performance Monitoring: What tools or techniques do you recommend for monitoring Suricata’s performance in real-time? I’d like to identify any bottlenecks or resource constraints that may be impacting performance.

I am eager to address these performance issues and ensure that Suricata 6.0.1 is running smoothly in my environment. I also check this : performance issues afterqlikviewenabling file resto But I have not found any solution.

Thank you all in advance! :smiling_face_with_three_hearts:

Respected community Member
Elean Elbert :innocent:

Suricata 6.0.1 is very old. At least go to 6.0.19 first, but ideally do straight to 7.0.5. 6.0.x will go end of life very soon.

Please upgrade per @vjulien’s message and let us know what the results are.

Be sure to include relevant information including

  • Suricata installation method (ppa, from source, etc)
  • Runtime environment (container, bare metal)
  • Host operating system
  • Hardware configuration (cpu type, core count, memory, NIC)
  • Suricata configuration details: packet source (e.g., af-packet, netmap, etc). CPU affinity settings
  • Suricata version – 6.0.19 or 7.0.5.