Suricata rule detecting malicious javascript with gzip

I’m trying do create a rule to alert for a malicious javascript in the php page and gzip
I need some help, please

Thanks

Do you some first rule to share ? Some more details ?