]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
dhcp: adds check for app-layer metadata logging in alerts master 3017/head
authorPhilippe Antoine <pantoine@oisf.net>
Tue, 7 Apr 2026 19:43:00 +0000 (21:43 +0200)
committerVictor Julien <vjulien@oisf.net>
Wed, 8 Apr 2026 20:44:48 +0000 (20:44 +0000)
Ticket: 6091

tests/dhcp-eve-extended/test.yaml

index e566ad6b244a16e92666487d5dc54740db2affd1..ffa293b966afa794377f9916ca3925f6e2299fe5 100644 (file)
@@ -73,6 +73,14 @@ checks:
     match:
       event_type: alert
       alert.signature_id: 1
     match:
       event_type: alert
       alert.signature_id: 1
+- filter:
+    requires:
+      min-version: 9
+    count: 1
+    match:
+      event_type: alert
+      alert.signature_id: 1
+      dhcp.type: reply
 - filter:
     requires:
       min-version: 7
 - filter:
     requires:
       min-version: 7