That’d be great if you could hint me a little bit.
I’m testing with replaying a pcap file via TCPReplay. I find that the count of the packets that TCPReplay replays(or displayed by Wireshark) and the packets that Suricata captures are always largely inconsistent.
There are 118690 packets in the PCAP.
Seems Suricata handled 71127 packets.
Checked with Ethtool and ifconfig, couldn’t get any clues if that’s due to NIC dropping.