I have IDS/IPS running on a few sites and haven’t had anyone report any slowness, but I’ll try to take a look and see if any of the CPU load looks high when the day gets a bit busier
It seems like it is an update process…so not likely the main process. Does it keep on running for long or only a short spike? If it hangs and runs indefinitely, then it is an issue of course.
I’m seeing the same on one of my Route 10’s very high load average (10+), suricata running away. Only checked as router had 2 random unexplained reboots today, saw this post, wondered if it was related.
Another issue I am seeing is, after some time logging only shows dnsmasg messages.
Nothing else is logged until I kill klogd process and then it runs fine for an hour or so.
Suricata does give the system a high load while it is starting, for about 1 minute. This is expected, then it will settle down once it has completed initialization.