suricata parses lowly in a large traffic
When suricata in NFQ mode,and I send a large traffic like 3,840kb/s,It shows a very low speed to parse the packages.I use 'ping' and the return time is 2634ms.So is there a good way to solve this problem?
Updated by Andreas Herz about 4 years ago
John Smith wrote:
do I need to change somethings in the suricata.yaml? If suricata in the NFQ mode
That depends, the only thing necessary is setting the queues when you run suricata (-q parameter).
But without more details about your setup, iptables rules etc. it's hard to tell you what might be the issue.