2 Questions on Suricata (Rules & Vs Zeek)

In ET are already quite some rules disabled. But you should try to run the whole ruleset (at least the default one) and start disabling rules. Unless you already spot some rules for protocols/traffic that you don’t expect to see.