SSH and SMTP rulesets

Anybody know of any good rulesets for monitoring incoming/outgoing SSH and SMTP connections?

If you just want to monitor, you could use the direct NSM output in Suricata.
What do you want to achieve exactly? See when SSH/SMTP is used or match on specific type of traffic?