We are running Suricata 7.0.3 on an Ubuntu server with multiple interfaces. Currently, we are testing with /24 subnets, but in the future, we plan to monitor a larger part of our organization, possibly using /16 subnets.
First, we would like to ask if you have any recommendations. Right now, each subnet is configured on a separate interface on the virtual server. Would it be better to have all the traffic on one interface? Does this depend on the capacity of the virtual network card or the amount of traffic being monitored?
Second, is there a limit to the number of interfaces Suricata can monitor?
Thank you.