good notes here
list all effective config:
suricata --dump-config
suricata -T -S "rules/malware.rules"
https://suricata.readthedocs.io/en/latest/rules/flow-keywords.html