This actually appears to be a bug in Suricata update not parsing the variable lists correctly. Its picking up part of the address group as a port group, seeing that port group doesn’t exist and disabling the rule. Looking into it.
1 Like