Rule grammar specification

Is Suricata rule grammar specified somewhere? EBNF or PEG notation would be ideal. I can’t find anything in the official documentation.

As far as we can tell, there isn’t such a specification. I have added a ticket in issue tracker, in case anyone from the community is willing and able to contribute with that :slight_smile: Documentation #4662: Add documentation section covering Suricata rule grammar - Suricata - Open Information Security Foundation