I would like to take advantage of the suricata.rules that is generated with suricata-update on an internet connected machine and transfer it to an airgapped machine.
What is the best approach to accomplish this? I’m thinking using the ruleset created through suricata-update as a local.rules.
I have similar setup, just that system is accessible through internal network but cannot access internet and i have to push rules from the suricata server having internet access, what is the best way here @ish please comment