That it does not store too many files
--- /dev/null
+# Description
+
+Test filestore does not store too much
+
+# Ticket
+
+https://redmine.openinfosecfoundation.org/issues/6390
+
+# PCAP
+
+The pcap was manually crafted to have HTTP/1 pipelining POST request with multipart files when the first response is not over
--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ types:
+ - files
+ - alert
+ - http
+ - file-store:
+ version: 2
+ enabled: yes
+ force-filestore: no
+ stream-depth: 0
--- /dev/null
+alert http any any -> any any (msg:"FILE HTTP filtore"; http.uri; content: "pipeline"; filestore:both,flow; sid:2; rev:1;)
--- /dev/null
+requires:
+ min-version: 8
+
+args:
+- -k none
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: fileinfo
+ fileinfo.sha256: eb076a2ec6ced9ee2e823e098446513cf5b2bb60fbcb04e6c85dc23dedaa414a
+ fileinfo.stored: false