Suricata Rule using GRE

Hi! I’m new to using Suricata.
I was trying to create a rule for GRE detection. So far, using ip_proto:47 works perfectly, but I’d like to be more specific and differentiate between GRE encapsulating Ethernet (GRE | ETH | IP | UDP) and GRE encapsulating IP (GRE | IP | UDP). I tried looking for information about GRE and Suricata but couldn’t find much.

Thank you! :slight_smile:

I don’t think there are any rule keywords for this. Could you open a feature ticket describing the use case(s)?