Skip to content

Commit

Permalink
tests: engine-analysis pkt_stream rule type tests
Browse files Browse the repository at this point in the history
To accompany Rule Types documentation.

Related to
Task #7031
  • Loading branch information
jufajardini committed Jan 27, 2025
1 parent 88fa0b6 commit 511c734
Show file tree
Hide file tree
Showing 2 changed files with 23 additions and 0 deletions.
3 changes: 3 additions & 0 deletions tests/rules/rule-type-pkt-stream/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Packet Stream rules
alert tcp any any -> any any (msg:"tcp, anchored content"; content:"abc"; startswith; sid:303;)
alert http any any -> any any (msg:"http, anchored content"; content:"abc"; depth:30; sid:603;)
20 changes: 20 additions & 0 deletions tests/rules/rule-type-pkt-stream/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
requires:
min-version: 7
pcap: false

args:
- --engine-analysis

checks:
- filter:
filename: rules.json
count: 1
match:
id: 303
type: pkt_stream
- filter:
filename: rules.json
count: 1
match:
id: 603
type: pkt_stream

0 comments on commit 511c734

Please sign in to comment.