-Test ldap.request.dn keyword.
+Test ldap.request.dn and
+ldap.responses.dn keywords.
PCAP from ../ldap-search/ldap.pcap
alert ldap any any -> any any (msg:"Test ldap request dn"; ldap.request.dn; content:"dc=example,dc=com"; startswith; endswith; sid:1;)
+alert ldap any any -> any any (msg:"Test ldap responses dn"; ldap.responses.dn; content:"dc=example,dc=com"; startswith; endswith; sid:2;)
\ No newline at end of file
ldap.request.operation: search_request
ldap.request.search_request.base_object: dc=example,dc=com
alert.signature_id: 1
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ pcap_cnt: 6
+ ldap.responses[0].operation: search_result_entry
+ ldap.responses[0].search_result_entry.base_object: dc=example,dc=com
+ alert.signature_id: 2