Packets dropping or not

Hello there,

That’d be great if you could hint me a little bit.
I’m testing with replaying a pcap file via TCPReplay. I find that the count of the packets that TCPReplay replays(or displayed by Wireshark) and the packets that Suricata captures are always largely inconsistent.

There are 118690 packets in the PCAP.
image

Seems Suricata handled 71127 packets.

Checked with Ethtool and ifconfig, couldn’t get any clues if that’s due to NIC dropping.

For testing you could run tcpdump on that interface and check if you receive all packets. At least it’s already a big diff between the NIC stats and the pcap, so they could have been lost on the wire.