First of all I just noticed you are using 6.0.0 beta1, please use the stable 6.0.10 release.
Second, you can chance the prio section in the affinity to also use just the core 0 and in addition to that feel free to try out the detect-thread-ratio setting and reduce it to 0.5 or even lower.
I personally never tried it on windows, so see those second points just as possible suggestion. Also what CPU is used in that scenario?
Hi @Andreas_Herz
I used 6.0.0 beta1 because in that installer, windivert was enabled. I tried with the 6.0.10, but windivert was disabled.
I tried with with the points which you shared, by reducing thread-ratio, but the thread count was not set to 1.
I am using it on the machine with 8 CPU and 8 cores.
If there is any other solution, please share it.
Thank you.
Hi @vjulien
Thank you for sharing the link.
I installed this and tried to run suricata with windivert and made the changes in the configuration file to make it single threaded, but still it runs in multi-threaded mode itself.