Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
Suricata needs all available RAM
« previous
next »
Print
Pages: [
1
]
Author
Topic: Suricata needs all available RAM (Read 3348 times)
PotatoCarl
Full Member
Posts: 134
Karma: 5
Suricata needs all available RAM
«
on:
November 06, 2019, 09:48:45 am »
Hi
I am running on a Deciso appliance and I enabled Suricata. However, it hogs up 4 of 4GB ram and after a couple of days it breaks the machine. Especially when I update all rules reproducible. I found this actually when I checked the rules and found that they have - despite the cron job - not been updated for 5 months, expect one.
Is this a) a memory leak that is a bug or b) is there a way to configure it with less use of memory. Is there a recommended configuration?
I use a longer list of rules, like snort, ET, OpenSense, abuse.
Thanks for you help.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Suricata needs all available RAM
«
Reply #1 on:
November 06, 2019, 12:14:46 pm »
URLhaus is quite a huge list .. maybe at first you should start with a small set of enabled rules?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
PotatoCarl
Full Member
Posts: 134
Karma: 5
Re: Suricata needs all available RAM
«
Reply #2 on:
November 06, 2019, 12:23:15 pm »
thank you. Which one is URLhaus?
Logged
PotatoCarl
Full Member
Posts: 134
Karma: 5
Re: Suricata needs all available RAM
«
Reply #3 on:
November 06, 2019, 02:52:08 pm »
Okay, found it, removed it, but nothing solved. Same problem. Takes a couple of minutes and ram load jumps from 60 to 96%, system slows aaaaaand stops.
Saw in another thread here that there are maybe some bugs with the 5.0 version I am using at this time (19.7.6) so maybe with 19.7.7 it will be okay. I hope.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Suricata needs all available RAM
«
Reply #4 on:
November 06, 2019, 04:35:39 pm »
Can you check the logs? Suricata 5 is only shipped in devel mode.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
PotatoCarl
Full Member
Posts: 134
Karma: 5
Re: Suricata needs all available RAM
«
Reply #5 on:
November 06, 2019, 05:21:04 pm »
logs say "empty".
Under "alarms" I have only 7 "allowed" entries, nothing else.
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Suricata needs all available RAM
«
Reply #6 on:
November 06, 2019, 05:36:49 pm »
Are you sure? 19.7.6 does not have Suricata 5, only the development equivalent.
Logged
cloudz
Jr. Member
Posts: 57
Karma: 4
Re: Suricata needs all available RAM
«
Reply #7 on:
November 10, 2019, 02:32:36 pm »
I'm experiencing exactly the same. Running OPNSense on a VM in ProxMox.
After enabling suricata - traffic still flows but the webinterface / ssh & even the console via ProxMox aren't responding anymore. CPU jumps up to 60/70% and stays there.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
Suricata needs all available RAM