]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
tftp: improves check for alert app-layer data
authorPhilippe Antoine <pantoine@oisf.net>
Thu, 11 May 2023 09:21:32 +0000 (11:21 +0200)
committerVictor Julien <victor@inliniac.net>
Tue, 21 Nov 2023 05:47:35 +0000 (06:47 +0100)
tests/output-eve-tftp-01/test.yaml

index b83cefc3ebb81d464060a09fca88c44fa1689d7d..814c80d54ba98c506be8de7cf6fa58c223be48b1 100644 (file)
@@ -15,3 +15,9 @@ checks:
     count: 1
     match:
       event_type: alert
+- filter:
+    min-version: 8
+    count: 1
+    match:
+      event_type: alert
+      tftp.packet: "read"