# Snort rules for Suricata-IDS

**URL:** <https://forum.suricata.io/t/snort-rules-for-suricata-ids/614>\
**Category:** Rules\
**Created:** [September 18, 2020, 11:31am UTC](https://forum.suricata.io/t/snort-rules-for-suricata-ids/614 "2020-09-18T11:31:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@Hack3rcon](https://forum.suricata.io/u/Hack3rcon)\
**Post date:** [September 18, 2020, 11:31am UTC](https://forum.suricata.io/t/snort-rules-for-suricata-ids/614/1 "2020-09-18T11:31:13Z")

</div>

Hello,  
Is it possible to use Snort rules file for Suricata-IDS?

Thank you.

---

<div class="post-metadata">

**Author:** ![jae](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jae/32/69_2.png) [@jae](https://forum.suricata.io/u/jae)\
**Post date:** [September 18, 2020, 3:29pm UTC](https://forum.suricata.io/t/snort-rules-for-suricata-ids/614/2 "2020-09-18T15:29:57Z")

</div>

It depends on what version of snort you are loading.

If you load 2.9.x Snort rules into Suricata, some rules will work, but will not run as well as rules that have been written specifically for Suricata. Snort rules that use the Shared Object features will not work in Suricata. Rules written specifically for Snort 3 will not work.

> **[6.32. Differences From Snort — Suricata 5.0.3 documentation](https://suricata.readthedocs.io/en/latest/rules/differences-from-snort.html)**

ET/ETPRO rules support both Suricata and Snort rule engines, so if using those, just make sure you are using the right rule file.

---

<div class="post-metadata">

**Author:** ![Cannoli](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Cannoli](https://forum.suricata.io/u/Cannoli)\
**Post date:** [February 25, 2024, 1:47am UTC](https://forum.suricata.io/t/snort-rules-for-suricata-ids/614/3 "2024-02-25T01:47:52Z")

</div>

How do I know I’m using the right rule file? If I’m using Suricata 6.x, which snort rules are equivalent? What about Suricata 7.x?

I tried loading Snort Subscription rules snort-snapshot-29xxx.tar.gz and received a bunch of errors when loading the rules with suricata-update. What did I do wrong? Should I use --no-test?

---

<div class="post-metadata">

**Author:** ![bmeeks](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bmeeks](https://forum.suricata.io/u/bmeeks)\
**Post date:** [February 25, 2024, 7:09pm UTC](https://forum.suricata.io/t/snort-rules-for-suricata-ids/614/4 "2024-02-25T19:09:42Z")

</div>

As was mentioned above, many of the Snort rules will not compile properly in the Suricata rules engine. This is because Suricata is not Snort 🙂. The rules syntax differs in certain ways. It is normal to see a number of the Snort rules produce errors when Suricata attempts to load them. Suricata discards those rules and does not load them after printing the error in the log.
