--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filetype: regular
+ filename: eve.json
+ types:
+ - mqtt
+ - alert
+
+app-layer:
+ protocols:
+ mqtt:
+ enabled: yes
\ No newline at end of file
--- /dev/null
+alert mqtt any any -> any any (msg:"MQTT CONNACK reason code 0"; mqtt.type:CONNECT,0; mqtt.type:CONNACK,1; mqtt.reason_code:0; sid:4;)
+
--- /dev/null
+requires:
+ min-version: 9
+
+args:
+ - -k none
+
+pcap: ../mqtt-connect-rules/mqtt5_pub_jpeg.pcap
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 4