]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
test: issue 4759
authorJason Ish <jason.ish@oisf.net>
Fri, 17 Feb 2023 18:33:15 +0000 (12:33 -0600)
committerVictor Julien <victor@inliniac.net>
Thu, 30 Mar 2023 13:55:09 +0000 (15:55 +0200)
tests/issues/issue-4759.1/README.md [new file with mode: 0644]
tests/issues/issue-4759.1/tcpdns.pcap [new file with mode: 0644]
tests/issues/issue-4759.1/test.rules [new file with mode: 0644]
tests/issues/issue-4759.1/test.yaml [new file with mode: 0644]

diff --git a/tests/issues/issue-4759.1/README.md b/tests/issues/issue-4759.1/README.md
new file mode 100644 (file)
index 0000000..6ebb6e5
--- /dev/null
@@ -0,0 +1 @@
+Test for issue 4759. Also related to 5799.
diff --git a/tests/issues/issue-4759.1/tcpdns.pcap b/tests/issues/issue-4759.1/tcpdns.pcap
new file mode 100644 (file)
index 0000000..c1ff33a
Binary files /dev/null and b/tests/issues/issue-4759.1/tcpdns.pcap differ
diff --git a/tests/issues/issue-4759.1/test.rules b/tests/issues/issue-4759.1/test.rules
new file mode 100644 (file)
index 0000000..26dac02
--- /dev/null
@@ -0,0 +1,2 @@
+alert tls any any -> any any (msg:"SSL Fingerprint"; sid:1; rev:1;)
+alert dns any any -> any any (msg:".com in DNS query"; dns.query; content:".com"; sid:2; rev:1;)
diff --git a/tests/issues/issue-4759.1/test.yaml b/tests/issues/issue-4759.1/test.yaml
new file mode 100644 (file)
index 0000000..e3063ca
--- /dev/null
@@ -0,0 +1,9 @@
+checks:
+  - filter:
+      count: 2
+      match:
+        event_type: alert
+  - filter:
+      count: 4
+      match:
+        event_type: dns