Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Suricata behavior
« previous
next »
Print
Pages: [
1
]
Author
Topic: Suricata behavior (Read 816 times)
someone
Full Member
Posts: 115
Karma: 2
Suricata behavior
«
on:
June 10, 2024, 10:46:32 pm »
I have run suricata on different linux distros
Note: I noticed after making a rule change and applying it(command line in linux)
It takes up to 5 minutes for surricata to parse, load, and start engine of 150,000 rules
You can see it in opnsense monitoring cpu
Its a off then on load on cpu, its not continuous I guess not to overheat cpu
But that means when you push apply you have to wait at least 5 minutes to make another rule change
Including policies
I wonder if that is what is effecting some changes, not giving it enough tiime to finish last job
Surricata doesnt do multiple commands
Logged
Greg_E
Sr. Member
Posts: 342
Karma: 19
Re: Suricata behavior
«
Reply #1 on:
June 11, 2024, 03:36:48 pm »
I have not noticed more than about 30 seconds to reload once I hit apply. AMD V1756B with 16gb of ram using the ET Open rule set.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Suricata behavior