The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Suricata Snort

Prev Next

The Suricata Snort engine provides a dedicated Snort environment and supports most of the open-source Snort constructs that are available in the public domain. This allows you to import most custom and third-party Snort rules without modification.

The usage of some of the constructs differ in Suricata Snort when compared with the open-source Snort. For more information on the differences, see http://suricata.readthedocs.io/en/latest/rules/differences-from-snort.html

Some of the open-source Snort constructs that are not supported in the Suricata Snort are as follows:

  • activated_by
  • activates
  • byte_jump bitmask
  • content http_header
  • content http_raw_cookie
  • cvs invalid-entry
  • flowbits reset
  • flowbits setx
  • gtp_info
  • gtp_type
  • gtp_version
  • http_encode*
  • ipopts lsrre
  • logto
  • modbus_*
  • pcre modifiers:
    • D
    • K
    • SIP (combination of S, I, and P modifiers)
  • protected_content*
  • react
  • resp
  • sip_*

Note

There can be other open-source constructs which are not supported in the Suricata Snort.

The following is the list of considerations when using the Suricata Snort:

  • You can import only the Suricata rules having tcp, udp, ip, and icmp protocols without modification from the Emerging Threats.
  • You cannot push the Suricata Reference config file to the Sensor.
  • You cannot import rule variables from yaml file from the Emerging Threats.
  • You cannot exclude a rule for a particular snort engine.