Project

General

Profile

Actions

Support #3132

closed

suricata can't capture all the packets

Added by yg lu about 5 years ago. Updated about 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Affected Versions:
Label:

Description

i try lots of tests to capture http packets use suricata, every time when i stop the capture, it tells me no packets drops, but actually what i send data it didn't capture all
so i try another test, i use tcpdump to capture the data and start suricata at the same time , i sent 5data tcpdump capture all but suricata capture 0 and when i stop , it tells me 0 packet drop.
i've no idea about this please give some helps
other tips:
1. i use pfring, actually the traffic is very small , 3000-5000pps
2. i test only 1 rule


Files

111.jpg (31.9 KB) 111.jpg tcpdump data yg lu, 08/29/2019 08:59 AM
rule.jpg (32.4 KB) rule.jpg suricata rule (only 1) yg lu, 08/29/2019 08:59 AM
suricata01.jpg (64.5 KB) suricata01.jpg suricata tells me 0 drop yg lu, 08/29/2019 08:59 AM
networkpic.png (99.7 KB) networkpic.png yg lu, 08/31/2019 03:28 AM
Actions

Also available in: Atom PDF