I have IDS/IPS running on a few sites and haven’t had anyone report any slowness, but I’ll try to take a look and see if any of the CPU load looks high when the day gets a bit busier
It seems like it is an update process…so not likely the main process. Does it keep on running for long or only a short spike? If it hangs and runs indefinitely, then it is an issue of course.
I’m seeing the same on one of my Route 10’s very high load average (10+), suricata running away. Only checked as router had 2 random unexplained reboots today, saw this post, wondered if it was related.
Another issue I am seeing is, after some time logging only shows dnsmasg messages.
Nothing else is logged until I kill klogd process and then it runs fine for an hour or so.
Suricata does give the system a high load while it is starting, for about 1 minute. This is expected, then it will settle down once it has completed initialization.
This thread has been automatically closed due to inactivity. If you believe you have the same issue, please create a new post describing your issue. Feel free to link to this post for context if desired.