As title details - there is a old suricata bug I am experiencing:
$suricata -T -c suricata.yaml 23/11/2017 -- 09:33:27 - <Info> - Running suricata under test mode Illegal instruction
This is detailed here
summary fix is simple, just add to .configure
--disable-gccmarch-native
Cheers
PS: And yes, that does have some performance hit but without it a bunch of machines fail