From: Philippe Antoine Date: Mon, 8 Sep 2025 08:51:50 +0000 (+0200) Subject: snmp: adds test for pdu_type keyword X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=e576599567aa1d33f666f49bfeea1738b76d50b1;p=thirdparty%2Fsuricata-verify.git snmp: adds test for pdu_type keyword Ticket: 6723 --- diff --git a/tests/snmp-pdu-type/README.md b/tests/snmp-pdu-type/README.md new file mode 100644 index 000000000..3b436c61a --- /dev/null +++ b/tests/snmp-pdu-type/README.md @@ -0,0 +1,7 @@ +# Test Purpose + +Match on SNMP pdu_type keyword + +## PCAP + +This PCAP from snmp-v2c-get is reused diff --git a/tests/snmp-pdu-type/test.rules b/tests/snmp-pdu-type/test.rules new file mode 100644 index 000000000..03514a40b --- /dev/null +++ b/tests/snmp-pdu-type/test.rules @@ -0,0 +1,2 @@ +alert snmp any any -> any any (msg:"SNMP Test Rule"; snmp.pdu_type: get_next_request; sid:1; rev:1;) +alert snmp any any -> any any (msg:"SNMP Test Rule"; snmp.pdu_type: 1; sid:2; rev:1;) diff --git a/tests/snmp-pdu-type/test.yaml b/tests/snmp-pdu-type/test.yaml new file mode 100644 index 000000000..580f079e0 --- /dev/null +++ b/tests/snmp-pdu-type/test.yaml @@ -0,0 +1,19 @@ +requires: + min-version: 9 + +pcap: ../snmp-v2c-get/SNMPv2c_get_requests.pcap + +checks: + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1 + snmp.pdu_type: get_next_request + + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 2 + snmp.pdu_type: get_next_request