The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Suricata Snort

Prev Next

The Suricata Snort engine provides a dedicated Snort environment and supports many of the open-source Snort constructs that are available in the public domain. This allows you to import most custom and third-party Snort rules without modification.

Trellix IPS uses Suricata Snort version 3.2.3. The usage of some of the constructs differs in Suricata Snort when compared to the open-source Snort. See https://docs.suricata.io/en/suricata-3.2.3/rules/http-keywords.html for the list of supported constructs.

The following is the list of considerations when using the Suricata Snort:

  • You can import only the Suricata rules having TCP, UDP, IP, and ICMP protocols without modification from the Emerging Threats.

  • You cannot push the Suricata Reference config file to the Sensor.

  • You cannot import rule variables from the yaml file from the Emerging Threats.

  • You cannot exclude a rule for a particular snort engine.

Note

The Suricata Snort engine is not available on NS9600, NS7600 and NS3600 Sensors.