No problems, I hope it helps.
Maybe these could offer some clarity:
- 6.1. Rules Format — Suricata 7.0.0-rc1-dev documentation
- 9.7. Ignoring Traffic — Suricata 7.0.0-rc1-dev documentation
Oh, I just saw this answer that is about pass rules, too: In Suricata IDS mode. is it possible to block/drop/pass good traffic so it will not be seen in kibana? - #15 by sscally
Good luck with your learning journey!