OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: someone on June 23, 2024, 06:44:52 PM

Title: Measure suricata rule reload lag time
Post by: someone on June 23, 2024, 06:44:52 PM
ok when the apply button is clicked in the IDS/IPS section under rules it will get a spinning circle to the side
When it quits is not the time it takes for a rule reload
When it stops spinning your rules are still loading
The amount of rules enabled effects the time

To see the actual rule reload time
After clicking the apply button, and after the circle next to apply stops spinning
Go to IDS/IPS section and go to logging
In the box change to informational
Look for  .. rule reload started
Rule reload complete
And figure the time between those two
It will not be finished till long after the apply button circle stops spinning
I would not give it another rule command till its finished
Mine with default rules enabled takes about one minute twenty seconds
Thats your real rule reload time
Title: Re: Measure suricata rule reload lag time
Post by: someone on June 23, 2024, 06:58:51 PM
oh, you will have to click on the refresh button in logging a few times and wait for rule reload complete to appear