The Suricata Snort engine provides a dedicated Snort environment and supports most of the open-source Snort constructs that are available in the public domain. This allows you to import most custom and third-party Snort rules without modification.
The usage of some of the constructs differ in Suricata Snort when compared with the open-source Snort. For more information on the differences, see http://suricata.readthedocs.io/en/latest/rules/differences-from-snort.html
Some of the open-source Snort constructs that are not supported in the Suricata Snort are as follows:
- activated_by
- activates
- byte_jump bitmask
- content http_header
- content http_raw_cookie
- cvs invalid-entry
- flowbits reset
- flowbits setx
- gtp_info
- gtp_type
- gtp_version
- http_encode*
- ipopts lsrre
- logto
- modbus_*
- pcre modifiers:
- D
- K
- SIP (combination of S, I, and P modifiers)
- protected_content*
- react
- resp
- sip_*
Note
There can be other open-source constructs which are not supported in the Suricata Snort.
The following is the list of considerations when using the Suricata Snort:
- You can import only the Suricata rules having tcp, udp, ip, and icmp protocols without modification from the Emerging Threats.
- You cannot push the Suricata Reference config file to the Sensor.
- You cannot import rule variables from yaml file from the Emerging Threats.
- You cannot exclude a rule for a particular snort engine.