Suricata-IDS eating memory!

What is you start command ? And could you please also share

suricata --dump-config |grep af-packet

if you are using the default settings (af-packet).

As a test run you could also try to start Suricata without rules and see if any difference

suricata ...... -S /dev/null
1 Like