No, I don’t do anything advanced with the suricata data. I just give them to Pakon to provide me with some statistics.
I’m not sure if you’ve stumbled upon one of the most interesting features of the turris routers - the distributed dynamic firewall. In Turris OS 3.x (“oldstable”), it was based on ucollect, in Turris OS 5.0 (“stable”) it is based on a custom data collection system called Sentinel. It collects various threat data, which are processed by CZ.NIC and they distill firewall rules which are then dynamically distributed to all turris routers. I’m not sure if these systems cooperate with suricata or not, but I think it’s possible. However, Sentinel is probably not a full IDS/IPS solution.