If the NIC’s ring buffer, which briefly holds incoming packets, is small, a sudden burst overflows it and packets get dropped.
Why The ring buffer is left at its small default (256–2,048 slots depending on the driver) → Effect During a burst, the buffer overflows before the CPU can pull packets off → On screen Loss only at burst moments (teleporting, skills not going off). No trace in the game server logs
Enlarge the ring buffer (ethtool -G), watch drop counters (such as rx_missed_errors in ethtool -S; names vary by driver).
Ballpark numbers
At 1 million packets per second, 1,024 slots fill in about 1 ms. If the CPU is late even once in that window, the buffer overflows. Most NICs can be raised to several thousand slots.
On the graph
Random spikes · NIC receive drop counters
Where to look
Collect the receive drop counters in ethtool -S (rx_missed_errors, rx_fifo_errors, and so on; names vary by driver) and missed in ip -s -s link at short intervals, and check the current and maximum ring size with ethtool -g
Confirmed if
Drop counters rise at burst moments, and the current ring size is far below the maximum. Enlarging the ring reduces the drops
Ruled out if
Drop counters flat but loss present: the next stage in the kernel (“Kernel socket buffers too small”) or the network path. One core’s %soft at 100%: “NIC interrupts concentrated on one core”
Interface statisticsLinux kernel Packets the device drops for lack of buffers are counted in rx_missed_errors; driver-specific stats are visible with ethtool -S
ethtool(8) — Linux manual pageethtool -g shows ring size (current and maximum), -G changes it, -S shows driver-specific stats