# Suricata 6/7 - Benefits or Problems of Midstream Pickup

**URL:** https://forum.suricata.io/t/suricata-6-7-benefits-or-problems-of-midstream-pickup/5364
**Category:** Help
**Tags:** configuration
**Created:** [February 13, 2025, 3:55pm UTC](https://forum.suricata.io/t/suricata-6-7-benefits-or-problems-of-midstream-pickup/5364 "2025-02-13T15:55:35Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![azuleonyx](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@azuleonyx](https://forum.suricata.io/u/azuleonyx)
#### Post date: [February 13, 2025, 3:55pm UTC](https://forum.suricata.io/t/suricata-6-7-benefits-or-problems-of-midstream-pickup/5364/1 "2025-02-13T15:55:35Z")

</div>

I am trying to understand the the benefits or problems with enabling midstream pickup. This funtionality is disabled in Suricata 6+ default but was enabled in Suricata 4.

Several years ago my employer switched from Suricata 4 to Suricata 6 (and we are in the process of moving to v7 soon). One of the things I noticed is this feature being enabled. Originally, my employeer used Yaff and they matched the Suricata 4 configuration to that.

At then moment, we get hundreds to thousands of alerts triggered through our client networks with midstream pickup. These alerts are not reviewed, because of the number of alerts generated and the uncertainly of the information.

My understanding is that that we can’t be sure of the direction or content of the traffic when this triggers. We do not currently use `async-oneside` either.

Should this be kept enabled for all installations or only enabled in some cases? I am trying to understand so we can either remove the configuration and stop generating the alerts we do not act on currently or figure out how to make the alerts more actiable in some way.

---

<div class="post-metadata">

### Author: ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)
#### Post date: [March 8, 2025, 8:22pm UTC](https://forum.suricata.io/t/suricata-6-7-benefits-or-problems-of-midstream-pickup/5364/2 "2025-03-08T20:22:55Z")

</div>

I would only enable it if you are certain that you need to pick up on midstream, but it would be better to ensure that you always see the full flow in Suricata.  
While the option being enabled might help with some cornercases it is better to ensure proper traffic forwarding.  
So in the end it depends on your environment and some testing.

---

<div class="post-metadata">

### Author: ![azuleonyx](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@azuleonyx](https://forum.suricata.io/u/azuleonyx)
#### Post date: [March 17, 2025, 1:50am UTC](https://forum.suricata.io/t/suricata-6-7-benefits-or-problems-of-midstream-pickup/5364/3 "2025-03-17T01:50:42Z")

</div>

@Andreas_Herz That’s a good question. I work for a MSSP with multiple customers and it has been enabled by default for all customer which creates a bunch of events which are not directly sent to customers. hmm.

---

<div class="post-metadata">

### Author: ![azuleonyx](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@azuleonyx](https://forum.suricata.io/u/azuleonyx)
#### Post date: [May 18, 2025, 11:55pm UTC](https://forum.suricata.io/t/suricata-6-7-benefits-or-problems-of-midstream-pickup/5364/4 "2025-05-18T23:55:45Z")

</div>

@Andreas_Herz Yeah, I am going to mark your comment as the solution. Networks can have some strange routing in them. Someone enabled it across all customers but it’s not really useful to have all the alerts be bubbled up without looking the networks.
