public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* Large Suricata cache directory.
@ 2025-12-12 16:49 Adam Gibbons
  2025-12-15 16:54 ` Michael Tremer
  0 siblings, 1 reply; 7+ messages in thread
From: Adam Gibbons @ 2025-12-12 16:49 UTC (permalink / raw)
  To: Development

Hi all,

As discussed on the forum
https://community.ipfire.org/t/re-large-backupfile/15346
it appears that Suricata’s new cache optimisation feature is creating a 
large number of files under
`/var/cache/suricata/sgh/`, which in some cases causes backup files to 
grow to 800+ MB.

@Adolf has confirmed that this directory probably should not be included 
in backups, as it is automatically regenerated, and I believe he 
mentioned he is working on a patch to exclude it from the backup.

However, in the meantime, this directory continues to grow over time. 
The upstream Suricata patches to automatically clean or maintain the 
cache have not yet been merged, although they may be soon:

https://github.com/OISF/suricata/pull/13850
https://github.com/OISF/suricata/pull/14400

To me this represents a disk-space exhaustion risk on systems with 
limited storage. Perhaps we should consider disabling Suricata’s new 
cache optimisation feature until automatic cache cleanup/maintenance is 
available upstream and included.

Thanks,
Adam


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2025-12-18 15:12 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-12-12 16:49 Large Suricata cache directory Adam Gibbons
2025-12-15 16:54 ` Michael Tremer
2025-12-15 17:09   ` Adolf Belka
2025-12-15 19:29   ` Adam Gibbons
2025-12-16 10:30     ` Michael Tremer
2025-12-16 12:45       ` Adolf Belka
2025-12-18 15:12         ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox