--- /dev/null
+alert tcp any any -> any any (msg:"Testing ack"; ack:782; sid:1;)
+alert tcp any any -> any any (msg:"Testing ack"; ack:15; sid:2;)
+alert tcp any any -> any any (msg:"Testing ack"; ack:437528; sid:3;)
\ No newline at end of file
--- /dev/null
+requires:
+ min-version: 8.0
+ pcap: false
+
+args:
+ - --engine-analysis
+
+checks:
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ lists.packet.matches[0].name: "tcp.ack"
+ lists.packet.matches[0].ack.number: 782
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 2
+ lists.packet.matches[0].ack.number: 15
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 3
+ lists.packet.matches[0].name: "tcp.ack"
+ lists.packet.matches[0].ack.number: 437528
\ No newline at end of file