1
21.1 Legacy Series / Re: Suricata IDS/IPS ~56% slower than before update
« on: August 24, 2021, 07:27:46 pm »
Yes, Its looks good when I started both IPS and sensei.
after few hours usually the problem occur.
When its happened, sensei engine will turn off automatically and I need to turn off IPS first before I can start back IPS and sensei once again.
netstat -ihw 1 also shows no drops.
packets errs idrops bytes packets errs bytes colls
3.7k 0 0 549K 2.3k 0 404K 0
3.5k 0 0 671K 2.3k 0 594K 0
4.5k 0 0 1.1M 3.0k 0 1.5M 0
3.9k 0 0 782K 2.4k 0 664K 0
4.3k 0 0 615K 3.0k 0 578K 0
3.9k 0 0 500K 2.0k 0 352K 0
3.2k 0 0 741K 2.1k 0 710K 0
3.3k 0 0 680K 1.5k 0 470K 0
3.0k 0 0 395K 1.5k 0 245K 0
4.2k 0 0 771K 2.2k 0 528K 0
2.4k 0 0 312K 1.3k 0 222K 0
3.5k 0 0 874K 1.9k 0 689K 0
2.7k 0 0 317K 1.4k 0 194K 0
4.2k 0 0 832K 2.2k 0 584K 0
3.6k 0 0 619K 2.1k 0 410K 0
4.8k 0 0 1.3M 3.2k 0 1.4M 0
2.9k 0 0 405K 1.9k 0 301K 0
22k 0 0 1.7M 20k 0 1.6M 0
5.3k 0 0 2.4M 3.1k 0 1.2M 0
5.5k 0 0 1.3M 4.2k 0 1.4M 0
3.6k 0 0 779K 2.6k 0 854K 0
input (Total) output
packets errs idrops bytes packets errs bytes colls
4.8k 0 0 1.2M 3.1k 0 1.2M 0
4.8k 0 0 987K 3.3k 0 807K 0
4.0k 0 0 736K 1.8k 0 316K 0
4.1k 0 0 930K 2.5k 0 777K 0
3.7k 0 0 544K 1.8k 0 313K 0
2.9k 0 0 478K 1.3k 0 243K 0
3.8k 0 0 614K 1.8k 0 343K 0
4.7k 0 0 1.2M 3.3k 0 1.5M 0
4.3k 0 0 596K 1.8k 0 275K 0
3.7k 0 0 808K 2.0k 0 725K 0
3.8k 0 0 736K 2.2k 0 483K 0
5.1k 0 0 869K 4.0k 0 594K 0
6.1k 0 0 886K 4.2k 0 1.3M 0
3.9k 0 0 536K 2.4k 0 354K 0
3.8k 0 0 580K 1.9k 0 398K 0
3.3k 0 0 519K 1.7k 0 302K 0
3.3k 0 0 508K 1.3k 0 236K 0
2.6k 0 0 413K 1.5k 0 399K 0
4.0k 0 0 568K 2.0k 0 384K 0
2.7k 0 0 426K 1.4k 0 340K 0
3.3k 0 0 730K 1.6k 0 425K 0
input (Total) output
packets errs idrops bytes packets errs bytes colls
2.8k 0 0 509K 1.5k 0 439K 0
5.3k 0 0 1.9M 2.9k 0 746K 0
4.1k 0 0 1.4M 3.1k 0 1.6M 0
7.8k 0 0 4.4M 3.2k 0 1.7M 0
2.7k 0 0 679K 1.6k 0 553K 0
2.7k 0 0 571K 1.3k 0 352K 0
2.4k 0 0 661K 1.3k 0 348K 0
3.3k 0 0 500K 1.7k 0 262K 0
3.1k 0 0 471K 2.1k 0 411K 0
I will let you know, if the problem occur once again.
So far I don't think hardware is the issues here.
I'm running with core i7, 32gb ram. 10g LACP on LAN and the ISP speed just 100mbps.
So it will be enough to handle the process right?
after few hours usually the problem occur.
When its happened, sensei engine will turn off automatically and I need to turn off IPS first before I can start back IPS and sensei once again.
netstat -ihw 1 also shows no drops.
packets errs idrops bytes packets errs bytes colls
3.7k 0 0 549K 2.3k 0 404K 0
3.5k 0 0 671K 2.3k 0 594K 0
4.5k 0 0 1.1M 3.0k 0 1.5M 0
3.9k 0 0 782K 2.4k 0 664K 0
4.3k 0 0 615K 3.0k 0 578K 0
3.9k 0 0 500K 2.0k 0 352K 0
3.2k 0 0 741K 2.1k 0 710K 0
3.3k 0 0 680K 1.5k 0 470K 0
3.0k 0 0 395K 1.5k 0 245K 0
4.2k 0 0 771K 2.2k 0 528K 0
2.4k 0 0 312K 1.3k 0 222K 0
3.5k 0 0 874K 1.9k 0 689K 0
2.7k 0 0 317K 1.4k 0 194K 0
4.2k 0 0 832K 2.2k 0 584K 0
3.6k 0 0 619K 2.1k 0 410K 0
4.8k 0 0 1.3M 3.2k 0 1.4M 0
2.9k 0 0 405K 1.9k 0 301K 0
22k 0 0 1.7M 20k 0 1.6M 0
5.3k 0 0 2.4M 3.1k 0 1.2M 0
5.5k 0 0 1.3M 4.2k 0 1.4M 0
3.6k 0 0 779K 2.6k 0 854K 0
input (Total) output
packets errs idrops bytes packets errs bytes colls
4.8k 0 0 1.2M 3.1k 0 1.2M 0
4.8k 0 0 987K 3.3k 0 807K 0
4.0k 0 0 736K 1.8k 0 316K 0
4.1k 0 0 930K 2.5k 0 777K 0
3.7k 0 0 544K 1.8k 0 313K 0
2.9k 0 0 478K 1.3k 0 243K 0
3.8k 0 0 614K 1.8k 0 343K 0
4.7k 0 0 1.2M 3.3k 0 1.5M 0
4.3k 0 0 596K 1.8k 0 275K 0
3.7k 0 0 808K 2.0k 0 725K 0
3.8k 0 0 736K 2.2k 0 483K 0
5.1k 0 0 869K 4.0k 0 594K 0
6.1k 0 0 886K 4.2k 0 1.3M 0
3.9k 0 0 536K 2.4k 0 354K 0
3.8k 0 0 580K 1.9k 0 398K 0
3.3k 0 0 519K 1.7k 0 302K 0
3.3k 0 0 508K 1.3k 0 236K 0
2.6k 0 0 413K 1.5k 0 399K 0
4.0k 0 0 568K 2.0k 0 384K 0
2.7k 0 0 426K 1.4k 0 340K 0
3.3k 0 0 730K 1.6k 0 425K 0
input (Total) output
packets errs idrops bytes packets errs bytes colls
2.8k 0 0 509K 1.5k 0 439K 0
5.3k 0 0 1.9M 2.9k 0 746K 0
4.1k 0 0 1.4M 3.1k 0 1.6M 0
7.8k 0 0 4.4M 3.2k 0 1.7M 0
2.7k 0 0 679K 1.6k 0 553K 0
2.7k 0 0 571K 1.3k 0 352K 0
2.4k 0 0 661K 1.3k 0 348K 0
3.3k 0 0 500K 1.7k 0 262K 0
3.1k 0 0 471K 2.1k 0 411K 0
I will let you know, if the problem occur once again.
So far I don't think hardware is the issues here.
I'm running with core i7, 32gb ram. 10g LACP on LAN and the ISP speed just 100mbps.
So it will be enough to handle the process right?
That looks ok, I am wondering if you can include the logs when IDS fails, It seems that it is running successfully.