--- /dev/null
+alert udp any any -> any any (content:"data|0a 0a|"; startswith; endswith; sid:1;)
- -k none
checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ src_ip: 10.0.0.1
+ dest_ip: 10.0.0.2
+ proto: UDP
+ src_port: 52377
+ dest_port: 52464
+ alert.signature_id: 1
- filter:
count: 1
match:
--- /dev/null
+alert udp any any -> any any (content:"data|0a 0a|"; startswith; endswith; sid:1;)
- -k none
checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ src_ip: 10.0.0.1
+ dest_ip: 10.0.0.2
+ proto: UDP
+ src_port: 52377
+ dest_port: 52464
+ alert.signature_id: 1
- filter:
count: 1
match: