Actions
Bug #4578
closedperf shows excessive time in IPOnlyMatchPacket
Affected Versions:
Effort:
Difficulty:
Label:
Description
With Suricata 5.0.x, perf
shows excessive time spent in IPOnlyMatchPacket
when there are rules containing IP addresses as filters. With roughly 400 rules and 15-20K IP addresses, perf
showed a majority of time spent in IPOnlyMatchPacket
.
Granted, a dataset is a better way to handle large IP address counts used within a rule but 5.0.x support didn't contain official dataset support.
Perhaps a warning or other indicator could be displayed to help users understand the effects of rules with large IP addr counts?
Files
Actions