From 1b7e92daef00b1c8c70192b1e6695d000c5993f4 Mon Sep 17 00:00:00 2001 From: Jeff Lucovsky Date: Tue, 13 Aug 2019 10:59:02 -0400 Subject: [PATCH] tests: Update anomaly logging to use new config --- .../anomaly.pcap | Bin tests/output-eve-anomaly-01/suricata.yaml | 11 +++++++ .../test.yaml | 7 ++++- tests/output-eve-anomaly-02/input.pcap | Bin 0 -> 978 bytes .../suricata.yaml | 1 - tests/output-eve-anomaly-02/test.yaml | 28 ++++++++++++++++++ tests/output-eve-anomaly-03/input.pcap | Bin 0 -> 978 bytes tests/output-eve-anomaly-03/suricata.yaml | 12 ++++++++ tests/output-eve-anomaly-03/test.yaml | 28 ++++++++++++++++++ .../suricata.yaml | 3 +- tests/output-eve-anomaly-packethdr/test.yaml | 8 ++++- 11 files changed, 94 insertions(+), 4 deletions(-) rename tests/{output-eve-anomaly => output-eve-anomaly-01}/anomaly.pcap (100%) create mode 100644 tests/output-eve-anomaly-01/suricata.yaml rename tests/{output-eve-anomaly => output-eve-anomaly-01}/test.yaml (78%) create mode 100644 tests/output-eve-anomaly-02/input.pcap rename tests/{output-eve-anomaly => output-eve-anomaly-02}/suricata.yaml (79%) create mode 100644 tests/output-eve-anomaly-02/test.yaml create mode 100644 tests/output-eve-anomaly-03/input.pcap create mode 100644 tests/output-eve-anomaly-03/suricata.yaml create mode 100644 tests/output-eve-anomaly-03/test.yaml diff --git a/tests/output-eve-anomaly/anomaly.pcap b/tests/output-eve-anomaly-01/anomaly.pcap similarity index 100% rename from tests/output-eve-anomaly/anomaly.pcap rename to tests/output-eve-anomaly-01/anomaly.pcap diff --git a/tests/output-eve-anomaly-01/suricata.yaml b/tests/output-eve-anomaly-01/suricata.yaml new file mode 100644 index 000000000..d56ffcb20 --- /dev/null +++ b/tests/output-eve-anomaly-01/suricata.yaml @@ -0,0 +1,11 @@ +%YAML 1.1 +--- + +outputs: + - eve-log: + enabled: yes + filetype: regular + types: + - anomaly: + types: + decode: yes diff --git a/tests/output-eve-anomaly/test.yaml b/tests/output-eve-anomaly-01/test.yaml similarity index 78% rename from tests/output-eve-anomaly/test.yaml rename to tests/output-eve-anomaly-01/test.yaml index c70239ddb..e9b6f8f17 100644 --- a/tests/output-eve-anomaly/test.yaml +++ b/tests/output-eve-anomaly-01/test.yaml @@ -9,11 +9,16 @@ args: - -k none checks: + - filter: + count: 0 + match: + event_type: anomaly + anomaly.type: stream - filter: count: 48 match: event_type: anomaly - anomaly.type: packet + anomaly.type: decode - filter: count: 4 match: diff --git a/tests/output-eve-anomaly-02/input.pcap b/tests/output-eve-anomaly-02/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..d50be332598fbf896b900c429b22f19b53bd3492 GIT binary patch literal 978 zc-p&ic+)~A1{MYcU}0bclCmbb5g|&f3|>Gs2s4O^^Rj)vak}g6LN^WuR|W=~Lk}Go z9M}@qa|tkV12JR60tT_e+%Fe`6fa;Z5=ho(U|?cl-NM4e!NvSh+W{ob$jrGcbTmR+$Jg6=XVtSi=Ib#B+i`(-$oeDpattLYT~W%eft7I?UvcK$D$- zraEDBv&o@HU^j0=bMqpg=|T+x3{P)50^P_6aWBYZkco;atPFiX!}_q9*l_4E*u+e% zCQ2|oowWzmM0eK^1$_mNkdOd=v|ueFwBm6BJc9PQU}!6=WGWs?u2*LV<>bVspBC z?{u)!-=R5O6Xx_7RTQVY1{CF&Gs2s4O^^Rj)vak}g6LN^WuR|W=~Lk}Go z9M}@qa|tkV12JR60tT_e+%Fe`6fa;Z5=ho(U|?cl-NM4e!NvSh+W{ob$jrGcbTmR+$Jg6=XVtSi=Ib#B+i`(-$oeDpattLYT~W%eft7I?UvcK$D$- zraEDBv&o@HU^j0=bMqpg=|T+x3{P)50^P_6aWBYZkco;atPFiX!}_q9*l_4E*u+e% zCQ2|oowWzmM0eK^1$_mNkdOd=v|ueFwBm6BJc9PQU}!6=WGWs?u2*LV<>bVspBC z?{u)!-=R5O6Xx_7RTQVY1{CF&