Is Suricata rule grammar specified somewhere? EBNF or PEG notation would be ideal. I can’t find anything in the official documentation.
Welcome to our forum ^^
As far as we can tell, there isn’t such a specification. I have added a ticket in issue tracker, in case anyone from the community is willing and able to contribute with that Documentation #4662: Add documentation section covering Suricata rule grammar - Suricata - Open Information Security Foundation