# Rule grammar specification

**URL:** <https://forum.suricata.io/t/rule-grammar-specification/1664>\
**Category:** Rules\
**Created:** [August 30, 2021, 2:25pm UTC](https://forum.suricata.io/t/rule-grammar-specification/1664 "2021-08-30T14:25:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmxmb](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@mmxmb](https://forum.suricata.io/u/mmxmb)\
**Post date:** [August 30, 2021, 2:25pm UTC](https://forum.suricata.io/t/rule-grammar-specification/1664/1 "2021-08-30T14:25:09Z")

</div>

Is Suricata rule grammar specified somewhere? EBNF or PEG notation would be ideal. I can’t find anything in the [official documentation](https://suricata.readthedocs.io/en/suricata-6.0.3/rules/index.html).

---

<div class="post-metadata">

**Author:** ![jufajardini](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jufajardini/32/896_2.png) [@jufajardini](https://forum.suricata.io/u/jufajardini)\
**Post date:** [September 3, 2021, 2:23pm UTC](https://forum.suricata.io/t/rule-grammar-specification/1664/2 "2021-09-03T14:23:28Z")

</div>

Hey there!

Welcome to our forum ^^

As far as we can tell, there isn’t such a specification. I have added a ticket in issue tracker, in case anyone from the community is willing and able to contribute with that 🙂 [Documentation #4662: Add documentation section covering Suricata rule grammar - Suricata - Open Information Security Foundation](https://redmine.openinfosecfoundation.org/issues/4662)
