Hi! I’m new to using Suricata.
I was trying to create a rule for GRE detection. So far, using ip_proto:47 works perfectly, but I’d like to be more specific and differentiate between GRE encapsulating Ethernet (GRE | ETH | IP | UDP) and GRE encapsulating IP (GRE | IP | UDP). I tried looking for information about GRE and Suricata but couldn’t find much.
Thank you! 