Hello Suricata community,
I am designing a network where I need to implement Suricata to monitor multiple subnets. I have the option of setting up multiple Suricata instances, each in a subnet with port mirroring configured on the corresponding switches, or using a single Suricata instance with multiple network interfaces capturing traffic from all subnets through port mirroring on a central switch. I would like to know which option is better in terms of performance, scalability, and ease of management. Additionally, I’d like to understand the potential impacts on traffic analysis and how to handle issues like bandwidth saturation if the monitoring is concentrated on a single server.
Any help or guidance is greatly appreciated!