The Suricata Snort engine provides a dedicated Snort environment and supports many of the open-source Snort constructs that are available in the public domain. This allows you to import most custom and third-party Snort rules without modification.
Trellix IPS uses Suricata Snort version 3.2.3. The usage of some of the constructs differs in Suricata Snort when compared to the open-source Snort. See https://docs.suricata.io/en/suricata-3.2.3/rules/http-keywords.html for the list of supported constructs.
The following is the list of considerations when using the Suricata Snort:
You can import only the Suricata rules having TCP, UDP, IP, and ICMP protocols without modification from the Emerging Threats.
You cannot push the Suricata Reference config file to the Sensor.
You cannot import rule variables from the yaml file from the Emerging Threats.
You cannot exclude a rule for a particular snort engine.
Note
The Suricata Snort engine is not available on NS9600, NS7600 and NS3600 Sensors.