According to the Suricata forum, Suricata 5.0.x is EOL from 1st Aug.
I know that the current testing build (Core 170) has the last supported version (5.0.10) released 12th July.
It may be time to move to Suricata 6.0.x. Upgrade notes can be found here
Do the IPFire devs have a plan for updating?
I’m shure they are more than aware.
I’m confident it will be upgraded
From the link above.
Anyone’s name sound familiar.
Arne Welzel, Eloy Pérez González, Eric Leblond, Michael Tremer, Sascha Steinbiss, Xiaofan Wang.
…and thank YOU, our community, for your ongoing support!
Michael you are a busy man.
Thanks for all you do.
I think they are working on 7.0 which would support JA3 again.
I had - and have - suricata 6/7 “still on my list”, but:
=> 12548 – Suricata 6.x causes high CPU load in Core Update 153 (testing)
Which leads to:
=> Bug #4379: flow manager: using too much CPU during idle - Suricata - Open Information Security Foundation
That’s the reason we’re still on 5.x. From Core 153 until now I’ve tested several 6.x versions - no change, high load.
As soon as I get hands on a 7.x version,I’ll test again.
suricata 6.0.6 today - start time was 7:57:44 am. The utilization rate rose from 1% to as high as 9.3% (idle):
System is: fireinfo.ipfire.org - Profile 5f68a6360ffbecb6877dcac75f5b8c8030f43ce8
They’re still working on it…
EDIT: After going back to
suricata 5.0.10, utilization dropped immediately to 0.0%-0.7% (idle).