]> git.ipfire.org Git - people/stevee/suricata-verify.git/commitdiff
tests/mac-eve-packet: check packet context metadata
authorSascha Steinbiss <satta@debian.org>
Sun, 8 Nov 2020 17:34:49 +0000 (18:34 +0100)
committerVictor Julien <victor@inliniac.net>
Thu, 3 Dec 2020 07:03:58 +0000 (08:03 +0100)
This refers to Redmine bug #4109.

tests/mac-eve-packet/suricata.yaml [new file with mode: 0644]
tests/mac-eve-packet/test.pcap [new file with mode: 0644]
tests/mac-eve-packet/test.rules [new file with mode: 0644]
tests/mac-eve-packet/test.yaml [new file with mode: 0644]

diff --git a/tests/mac-eve-packet/suricata.yaml b/tests/mac-eve-packet/suricata.yaml
new file mode 100644 (file)
index 0000000..56c9cc6
--- /dev/null
@@ -0,0 +1,11 @@
+%YAML 1.1
+---
+
+outputs:
+  - eve-log:
+      enabled: yes
+      filetype: regular
+      filename: eve.json
+      ethernet: yes
+      types:
+        - alert
diff --git a/tests/mac-eve-packet/test.pcap b/tests/mac-eve-packet/test.pcap
new file mode 100644 (file)
index 0000000..0f19a2e
Binary files /dev/null and b/tests/mac-eve-packet/test.pcap differ
diff --git a/tests/mac-eve-packet/test.rules b/tests/mac-eve-packet/test.rules
new file mode 100644 (file)
index 0000000..41725c3
--- /dev/null
@@ -0,0 +1 @@
+alert ip any any -> any any (msg:"test"; sid:1;)
diff --git a/tests/mac-eve-packet/test.yaml b/tests/mac-eve-packet/test.yaml
new file mode 100644 (file)
index 0000000..59db8ba
--- /dev/null
@@ -0,0 +1,13 @@
+requires:
+  min-version: 6.0.0
+
+args:
+  - -k none
+
+checks:
+  - filter:
+      count: 2
+      match:
+        event_type: alert
+        ether.dest_mac: 00:25:90:e3:d2:e1
+        ether.src_mac: 0c:86:10:ed:d7:c6