+++ /dev/null
-#! /bin/sh
-
-. ../../util/functions.sh
-
-# Should have one fast log entry.
-n=$(cat output/fast.log | wc -l | xargs)
-assert_eq 1 "$n" "bad fast.log"
-
-# Should have one eve alert.
-n=$(jq_count output/eve.json 'select(.event_type == "alert")')
-assert_eq 1 "$n" "eve.json alerts"
-
-exit 0
--- /dev/null
+checks:
+
+ - shell:
+ args: cat output/fast.log | wc -l | xargs
+ expect: 1
+
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+++ /dev/null
-#! /bin/sh
-
-. ../../util/functions.sh
-
-# Should have one fast log entry.
-n=$(cat output/fast.log | wc -l | xargs)
-assert_eq 1 "$n" "bad fast.log"
-
-# Should have one eve alert.
-n=$(jq_count output/eve.json 'select(.event_type == "alert")')
-assert_eq 1 "$n" "eve.json alerts"
-
-exit 0
--- /dev/null
+checks:
+
+ # Check that we only have one alert event type in eve.
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+
+ # Check how many lines were logged to fast.log.
+ - shell:
+ args: cat output/fast.log | wc -l | xargs
+ expect: 1
- HAVE_LUA
checks:
- - signature-id: 1
- - signature-id: 2
- - signature-id: 3
+ - filter:
+ count: 1
+ match:
+ alert.signature_id: 1
+ - filter:
+ count: 1
+ match:
+ alert.signature_id: 2
+ - filter:
+ count: 1
+ match:
+ alert.signature_id: 3