Actions
Bug #4578
closedperf shows excessive time in IPOnlyMatchPacket
Affected Versions:
Effort:
Difficulty:
Label:
Description
With Suricata 5.0.x, perf
shows excessive time spent in IPOnlyMatchPacket
when there are rules containing IP addresses as filters. With roughly 400 rules and 15-20K IP addresses, perf
showed a majority of time spent in IPOnlyMatchPacket
.
Granted, a dataset is a better way to handle large IP address counts used within a rule but 5.0.x support didn't contain official dataset support.
Perhaps a warning or other indicator could be displayed to help users understand the effects of rules with large IP addr counts?
Files
Updated by Jeff Lucovsky almost 2 years ago
- Status changed from New to In Review
Updated by Victor Julien almost 2 years ago
- Assignee set to Justin Azoff
- Target version set to 7.0.0-rc2
Updated by Victor Julien over 1 year ago
- Status changed from In Review to Closed
- Label Needs backport to 6.0 added
Updated by Victor Julien over 1 year ago
- Status changed from Resolved to Closed
Updated by Andreas Herz over 1 year ago
Added a perf top output to see the impact of the patch
Actions