Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - TCMSLP

#1
Thanks Franco!

I have reverted suricata to 25.7.10 as you suggested.  With IDS/IPS enabled I now have very high memory consumption, but not to the point where everything falls apart.

last pid: 45631;  load averages:  0.60,  0.62,  0.42                                                                                                               up 0+18:34:05  12:46:35
77 processes:  1 running, 76 sleeping
CPU:  0.1% user,  0.0% nice,  0.2% system,  0.0% interrupt, 99.7% idle
Mem: 2151M Active, 92M Inact, 369M Laundry, 919M Wired, 56K Buf, 191M Free
ARC: 158M Total, 57M MFU, 59M MRU, 623K Anon, 1231K Header, 40M Other
     75M Compressed, 167M Uncompressed, 2.24:1 Ratio
Swap: 8192M Total, 3984M Used, 4208M Free, 48% Inuse

  PID USERNAME    THR PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
69656 root         13  20    0    11G  2319M nanslp   1   1:21   0.38% suricata

Perhaps, I'm at the point where I simply need more RAM.
I haven't paid attention to CPU/RAM utilisation previously as the box has 'just worked'.

Hopefully this will provide clues to others hitting this problem.
#2
Signed up to the forum to report exactly the same issue.  The box appears stable until I login, then memory consumption quickly climbs to 100% and the UI becomes unresponsive.  I've tried disabling host / neighbourhood discovery but this makes zero difference.

Update 1:
I've now identified the problem process:
USER      PID  %CPU %MEM      VSZ     RSS TT  STAT STARTED      TIME COMMAND
root    51727   0.1 58.8 11386908 2316112  -  Ss   17:35     1:52.31 /usr/local/bin/suricata -D --netmap --pidfile /var/run/suricata.pid -c /usr/local/etc/suricata/suricata.yaml

After identifying this, I disabled intrusion detection and now everything is back to normal.   

Update 2:
Re-enabling IDS (and IPS) immediately causes the issue again.  However, I'm now wondering if new rules/changes may have increased memory usage; perhaps using the web UI is adding to this demand/exhaustion.  Either way, disabling IDS has solved my immediate problem.

OPNsense 25.7.11_2, 4GB RAM, i5-4570.