Redmine issue:
https://redmine.openinfosecfoundation.org/issues/2490
--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filetype: regular
+ filename: eve.json
+ types:
+ - alert
--- /dev/null
+e19c1283c925b3206685ff522acfe3e6
--- /dev/null
+# filemd5 rule without filestore keyword.
+alert http any any -> any any (msg:"test"; filemd5: target.md5; classtype: bad-unknown; sid:1530024;)
+
+#alert http any any -> any any (msg:"test"; filemd5: target.md5; filestore; classtype: bad-unknown; sid:1530024;)
--- /dev/null
+requires:
+ features:
+ - HAVE_NSS
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: alert