I have a Suricata instance that does not have internet access. I currently update my Suricata rules using suricata-update pointing to a local file. I would like to incorporate Snort subscriber rules as well as the SUricata ET Open rules and need some information on how to do this. Do I just update the suricata-update --local= to point to the snort file?
Thank you for the reply. Since I’m already using the file option for suricata-update to point to my off-line Suricata ET rules, will adding the path to the snort-tar.gz file overwrite the path to the ET rules, or will it add a second file location option?