I agree with Derick. We love the product but do struggle with it. Every time I update, something goes wrong.
The latest quirk is when they moved suricata to the eve.json logging. I have some very high event per second sensors and when the log rotation tries to run nightly, it can't keep up. So the log file never gets closed properly and just keep growing and growing until it runs out of disk space and the sensor crashes.
I posted in the forums, and a few others seemed to have the same issues, and we came up with some fixes for the log rotation.
So far I have managed to recover two crashed sensors and got them working, but one I could not and tried to rebuild.
But the rebuild did not go so well since something changed recently and would not recognize some hardware on the box that was previously working fine.
So then I tried to install using the source code, but there was no instructions for using the source code. Kcoe replied to me that he would track down some instructions, but those never seemed to appear.
My shirt size is medium. Thanks!