How to effectively block all traffic which matches priority/severity level 1?

Great! Thanks. Didn’t know about it.

I was reading just only manual page - suricata-update(1).
There is no information about https://suricata-update.readthedocs.io/.
Would be nice if there was that link.

Finally, I’ve found how that manpage was created for Debian dist:

  1. https://salsa.debian.org/pkg-suricata-team/pkg-suricata-update/-/blob/master/debian/rules
  2. then via help2man which adds --help to program, so it becomes suricata-update --help

For groff(7) output (which produces help2man), URL probably should be placed within .UR and .UE macros, see groff_man(7).
In case it is entirely rewritten in mdoc(7) then need to use .Lk macro.