for content range header for instance
--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ types:
+ - files
+ - stats
+ - http:
+ custom: [Content-Range]
+ - file-store:
+ version: 2
+ enabled: yes
+ force-filestore: yes
+ stream-depth: 0
+
+app-layer:
+ protocols:
+ http:
+ enabled: yes
+ libhtp:
+ default-config:
+ personality: IDS
+ response-body-limit: 100kb
match:
event_type: fileinfo
fileinfo.size: 69
+ - filter:
+ count: 1
+ match:
+ event_type: http
+ http.response_headers[0].name: "Content-Range"
+ http.response_headers[0].value: "bytes 10-20/69"
- filter:
count: 0
match: