Use of Suricata and dpdk

Hello all,
I’m pretty new to IDS and Ask a question
1、Use the Suricata master branch dependency after dpdk-19.11 compiles.
./ -b igb_uio 0000:05:00.0
./ -b igb_uio 0000:06:00.0
./ -b igb_uio 0000:07:00.0
./ -b igb_uio 0000:08:00.0
./ --status-dev net
Network devices using DPDK-compatible driver

0000:05:00.0 ‘I211 Gigabit Network Connection 1539’ drv=igb_uio unused=igb
0000:06:00.0 ‘I211 Gigabit Network Connection 1539’ drv=igb_uio unused=igb
0000:07:00.0 ‘I211 Gigabit Network Connection 1539’ drv=igb_uio unused=igb
0000:08:00.0 ‘I211 Gigabit Network Connection 1539’ drv=igb_uio unused=igb

Network devices using kernel driver

0000:03:00.0 ‘I211 Gigabit Network Connection 1539’ if=enp3s0 drv=igb unused=igb_uio Active
0000:04:00.0 ‘I211 Gigabit Network Connection 1539’ if=enp4s0 drv=igb unused=igb_uio

vim /usr/local/etc/suricata/suricata.yaml
proc-type: primary

DPDK capture support

RX queues (and TX queues in IPS mode) are assigned to cores in 1:1 ratio

- interface: 0000:05:00.0 # PCIe address of the NIC port
# Threading: possible values are either “auto” or number of threads

Run suricata --dpdk
[root@RFW dpdk-stable-19.11.11]# suricata --dpdk
[11304] 10/1/2022 – 20:44:44 - (suricata.c:1138) (LogVersion) – This is Suricata version 7.0.0-dev (93842aa 2022-01-03) running in SYSTEM mode
EAL: No available hugepages reported in hugepages-1048576kB
[11304] 10/1/2022 – 20:44:44 - (runmode-dpdk.c:334) (ConfigSetIface) – [ERRCODE: SC_ERR_DPDK_CONF(343)] - Interface “0000:05:00.0”: No such device

The reason for the error is to obtain the network port_id, all network ports are invalid (unbound), but I use ./ binds the network port.
What are the other reasons?

1 Like


Have you had some problem with and LIBTOOL with Suricata v7 ?

First of all, thank you for your answer。
I have compiled Suricata master branch (V7) with dpdk-20.11, and then it can be used normally.
libdpdk.pc of pkgconfig will not be automatically generated for dpdk-19.11, and libdpdkpc of pkgconfig will be automatically generated after the compilation and installation of dpdk-20.11, which may be caused by the dependency problem when I rely on dpdk-19.11.

1 Like