Go to your data directory (default: /var/lib/suricata
)
cd /var/lib/suricata
There are two folders here update
and rules
.
rules
is the directory where the rules are finally written down either merged into suricata.rules
or separately in different files.
update
is the directory consisting of cache
and sources
. cache
consists of cached rules and these are the ones that are read by suricata update on a run.
Run suricata-update
forcefully before implementing any changes to the rules.