Thank you for your useful information.
Thus, When I use “suricata-update” then it pull all emerging rules and puts them into “suricata.rules” file?
If yes, then I don’t need to download all emerging rules separately?
I can’t see any “enable.conf” or “disable.conf” file:
# nano /etc/suricata/
classification.config rules/ threshold.config
reference.config suricata.yaml