Disable.conf not working

I do not have an enable.conf. My disable.conf file:
group:emerging-ciarmy.rules
group:emerging-dshield.rules

From the run:
14/4/2021 – 05:57:43 - – Loading /opt/suricata/etc/suricata/disable.conf.
14/4/2021 – 05:57:46 - – Disabled 14 rules.

yet still I see CINS rules in my suricata.rules file. Am I missing something? Thank you.

re:ET\ CINS works…tried groups without the .rules, still those don’t work.

I’m looking at the latest ET/Open rules and I don’t see a emerging-ciarmy or emerging-dshield, but I do see ciarmy.rules and dshield.rules. Try dropping the emerging-.

https://rules.emergingthreatspro.com/open-nogpl/snort-2.9.0/rules/

By default Suricata-Update will fetch the Suricata rules, not the Snort rules: Proofpoint Emerging Threats Rules

And these filenames to differ between the rulesets. Can you confirm which rules you are fetching?

Oh wow…ya missed that:

https://rules.emergingthreatspro.com/open-nogpl/suricata-5.0/rules/

Still same though…results:
group:ciarmy.rues
group:dshield.rules
group:drop.rules
group:compromised.rules
group:3coresec.rules
27/4/2021 – 12:42:20 - – Disabled 188 rules.

re:ET\ CINS
re:ET\ DROP
re:ET\ COMPROMISED
re:3CORESec
27/4/2021 – 12:43:13 - – Disabled 288 rules.

Check this typo. I think thats the source of 100 rules not being disabled.

Good eye Jason that was it…thank you!