I have an OPNsense firewall running on 23.1.1_2 firmware. Suricata package is 6.0.9_1. I have the OPNsense OS installed on physical hardware. The LAN port is apart of a LAN bridge in OPNsense. In the eve.json logs all of the log lines are showing traffic is getting dropped with the reason being stream error. We have to turn IDS off on OPNsense as accessing web pages is so slow we’re unable to get any work done. Below is an output of the stats.log
Date: 3/31/2023 – 23:37:20 (uptime: 0d, 00h 00m 59s)
Counter | TM Name | Value
capture.kernel_packets | Total | 21966
decoder.pkts | Total | 21966
decoder.bytes | Total | 17920318
decoder.ipv4 | Total | 21879
decoder.ipv6 | Total | 3
decoder.ethernet | Total | 21966
decoder.tcp | Total | 17547
decoder.udp | Total | 4305
decoder.icmpv4 | Total | 30
decoder.avg_pkt_size | Total | 815
decoder.max_pkt_size | Total | 1514
flow.tcp | Total | 202
flow.udp | Total | 149
flow.wrk.spare_sync_avg | Total | 100
flow.wrk.spare_sync | Total | 5
flow.wrk.flows_evicted_needs_work | Total | 85
flow.wrk.flows_evicted_pkt_inject | Total | 145
flow.wrk.flows_injected | Total | 85
tcp.sessions | Total | 95
tcp.syn | Total | 95
tcp.synack | Total | 95
tcp.rst | Total | 118
tcp.overlap | Total | 6
app_layer.flow.http | Total | 3
app_layer.tx.http | Total | 4
app_layer.flow.tls | Total | 84
app_layer.flow.dcerpc_tcp | Total | 3
app_layer.tx.dcerpc_tcp | Total | 14
app_layer.flow.ntp | Total | 3
app_layer.tx.ntp | Total | 3
app_layer.flow.krb5_tcp | Total | 5
app_layer.tx.krb5_tcp | Total | 5
app_layer.flow.snmp | Total | 1
app_layer.tx.snmp | Total | 42
app_layer.flow.dns_udp | Total | 129
app_layer.tx.dns_udp | Total | 257
app_layer.flow.failed_udp | Total | 16
flow.mgr.full_hash_pass | Total | 1
flow.spare | Total | 9500
flow.mgr.rows_maxlen | Total | 1
flow.mgr.flows_checked | Total | 39
flow.mgr.flows_notimeout | Total | 39
tcp.memuse | Total | 1212416
tcp.reassembly_memuse | Total | 196608
flow.memuse | Total | 7074304
Any help would be greatly appreciated. Let me know if any further information is required.