Suricata high capture.kernel_drops count. I use the PF_RING zc mode

Filestore is also quite resource intensive, but the perf top also indicates that maybe pf ring needs to be improved. The overhead of ring_is_not_empty would be worth a look.