--- /dev/null
+requires:
+ min-version: 6.0.0
+ files:
+ - src/util-macset.c
+
+args:
+ - -k none
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: flow
+ ether.dest_macs: ["00:00:0c:01:01:14","00:00:0c:01:01:12"]
+ ether.src_macs: ["00:00:0c:01:01:13","00:00:0c:01:01:11"]
--- /dev/null
+requires:
+ min-version: 6.0.0
+ files:
+ - src/util-macset.c
+
+args:
+ - -k none
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: flow
+ ether.dest_macs: ["0c:c4:7a:ac:83:d7"]
+ ether.src_macs: ["f8:59:71:a9:05:60"]
+
+ - filter:
+ count: 1
+ match:
+ event_type: dns
+ ether.src_mac: f8:59:71:a9:05:60
+ ether.dest_mac: 0c:c4:7a:ac:83:d7