Suricata default rules

Hi.

  1. SIDs are supposed to be unique identifiers for each rule in Suricata just like Snort. I am not aware of any ruleset using the same SID ranges as the Snort rules so there should not be any collisions. Not really sure what kind of answer you are looking for.

  2. The Suricata developers do not create their own extensive ruleset as Cisco does with Snort. There are however as you have noticed yourself multiple third party paid and free ruleset providers.
    The rules are of course not identical to the ones provided by Cisco so I guess the coverage will technically never be identical. I guess you will just have to evaluate rule sources and deem if they are “good enough”, just like you would have had to do with the Snort ruleset. I am not familiar enough with the snort ruleset to make an comparison myself.