--- /dev/null
+# Test Purpose
+
+Match on SNMP pdu_type keyword
+
+## PCAP
+
+This PCAP from snmp-v2c-get is reused
--- /dev/null
+alert snmp any any -> any any (msg:"SNMP Test Rule"; snmp.pdu_type: get_next_request; sid:1; rev:1;)
+alert snmp any any -> any any (msg:"SNMP Test Rule"; snmp.pdu_type: 1; sid:2; rev:1;)
--- /dev/null
+requires:
+ min-version: 9
+
+pcap: ../snmp-v2c-get/SNMPv2c_get_requests.pcap
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ snmp.pdu_type: get_next_request
+
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+ snmp.pdu_type: get_next_request