Suricata can trigger on a lot of things if you enabled _everything_For example, if you only have Windows laptops and iPhones then Microsoft Exchange or Oracle Weblogic rules don't need to be enabled.Out of 63864 entries chances are you're gonna hit enough times one or more generic rules that will quickly fill up storage
70K DoH/DoT servers seems a bit excessive, doubt there are that many to begin with...
Sure, most of them are regular servers, not DoH/DoT enabled and you wouldn't be hitting any of it with the DNS/53 intercept rules (need one for IPv6 btw)
It's on the bridge for me, and after upgrading to 23.7.2 I retested, same behaviour, the moment I enable logging on this particular rule, syslog-ng and filterlog processes go nuts.