# Questions about Suricata Multi-Tenancy Configuration Changes and Service Restart

**URL:** <https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183>\
**Category:** Uncategorized\
**Tags:** configuration, suricata\
**Created:** [December 27, 2024, 3:49am UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183 "2024-12-27T03:49:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![aaaaaaarror](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/aaaaaaarror/32/3346_2.png) [@aaaaaaarror](https://forum.suricata.io/u/aaaaaaarror)\
**Post date:** [December 27, 2024, 3:49am UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/1 "2024-12-27T03:49:12Z")

</div>

Hello,

I have some questions regarding Suricata’s multi-tenancy configuration management:

1. When a tenant’s configuration is modified, does Suricata require a complete service restart to load the new configuration?

2. If a service restart is required, how does this affect traffic analysis for other tenants? Are there any ways to avoid impacting other tenants during configuration changes?

3. Specifically, for tenant-specific configurations, which changes require a full service restart versus just a configuration reload:

I’m trying to understand the best practices for managing tenant configurations while minimizing service disruption in a production environment.

Thank you for your help!

Best regards

---

<div class="post-metadata">

**Author:** ![Steven](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@Steven](https://forum.suricata.io/u/Steven)\
**Post date:** [December 27, 2024, 5:05pm UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/2 "2024-12-27T17:05:54Z")

</div>

Hi,

I was just working on this and i’ve done it like this:

suricata.yaml:

> detect-engine:  
> - rule-reload: true

after modifying any of the rules I do:

> suricatasc -c ruleset-reload-nonblocking

source: [9.3. Rule Reloads — Suricata 8.0.0-dev documentation](https://docs.suricata.io/en/latest/rule-management/rule-reload.html)

I think as described in the manual this way there is a minimal service disruption on analyzing traffic.

Can I ask you what do you mean with a multi-tenancy configuration, you are running infrastructure for multiple clients on your system ?

Regards,  
Steven

---

<div class="post-metadata">

**Author:** ![Jeff\_Lucovsky](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jeff_lucovsky/32/11_2.png) [@Jeff\_Lucovsky](https://forum.suricata.io/u/Jeff_Lucovsky)\
**Post date:** [December 29, 2024, 2:28pm UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/3 "2024-12-29T14:28:42Z")

</div>

Hi,

Suricata can reload rules and rule variables without a complete service restart (I’m assuming you mean restarting the suricata process).

Suricata’s multi-tenancy documentation shows how to configure Suricata support for multiple-tenants.

The basic tenet of multi-tenancy (pun intended :-)) is to provide different rules, reference and classification config files, and rule variables for each tenant.

`suricatasc` supports reloading individual tenants when the rules, config files, and/or rule variables change.

---

<div class="post-metadata">

**Author:** ![aaaaaaarror](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/aaaaaaarror/32/3346_2.png) [@aaaaaaarror](https://forum.suricata.io/u/aaaaaaarror)\
**Post date:** [December 31, 2024, 3:02am UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/4 "2024-12-31T03:02:07Z")

</div>

Thank you for your response. As Jeff Lucovsky mentioned, multi-tenancy is what we’re referring to. Additionally, I have also practiced the relatively lossless rule reloading that you described.

---

<div class="post-metadata">

**Author:** ![aaaaaaarror](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/aaaaaaarror/32/3346_2.png) [@aaaaaaarror](https://forum.suricata.io/u/aaaaaaarror)\
**Post date:** [December 31, 2024, 3:03am UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/5 "2024-12-31T03:03:53Z")

</div>

Thank you Jeff for the detailed explanation. Now I understand that multi-tenancy in Suricata allows:

1. Different configurations for different tenants including:
  - Different rules
  - Different reference files
  - Different classification config files

2. And using suricatasc, we can reload configurations for individual tenants without affecting others.

I’ll check out the multi-tenancy documentation you linked for more details on the setup process.

---

<div class="post-metadata">

**Author:** ![Steven](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@Steven](https://forum.suricata.io/u/Steven)\
**Post date:** [December 31, 2024, 8:25am UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/6 "2024-12-31T08:25:37Z")

</div>

I was a little bit too fast when not fully awake 🙂

I understand after reading the post again, also interested in this topic did not know this was even possible.

From my understanding having a quick view at the Multi-Tenancy documentantion is that every VLAN can have its own ruleset, would be something to test for me in the future.

---

<div class="post-metadata">

**Author:** ![Steven](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@Steven](https://forum.suricata.io/u/Steven)\
**Post date:** [December 31, 2024, 8:27am UTC](https://forum.suricata.io/t/questions-about-suricata-multi-tenancy-configuration-changes-and-service-restart/5183/7 "2024-12-31T08:27:05Z")

</div>

@ [aaaaaaarror](https://forum.suricata.io/u/aaaaaaarror) I was a little bit too fast when not fully awake 🙂

I understand after reading the post again, also interested in this topic did not know this was even possible.

From my understanding having a quick view at the Multi-Tenancy documentation is that every VLAN or device (IPS not supported here, device looks like a network interface in the example) can have its own ruleset, would be something to test for me in the future.
