We’re trying to better understand this situation. Would you be able to provide a pcap showcasing the traffic that is generating more alerts when stream.inline is “yes”?
Also, could you tell us which version of Suri you are running, just so we have a bigger picture?
So far, as a heads-up, this may be a case of lack of documentation. If you set stream.inline: no you don’t get the increase, right? What happens if you keep that as no but pass the command-line option --simulate-ips? Are the results similar to having it as stream.inline: yes?
The results appear not to be similar. With stream.inline: auto and --simulate-ips i do not have the increase. In IDS mode should i leave this to “no” or “auto”?