--- /dev/null
+PCAP Source
+-----------
+
+https://www.pcapr.net/view/bortzmeyer+pcapr/2013/8/1/13/dns-notify.pcap.html
--- /dev/null
+alert dns any any -> any any (msg:"TEST OPCODE MATCH"; dns.opcode:4; flow:to_server; sid:1; rev:1;)
+alert dns any any -> any any (msg:"TEST OPCODE NEGATED MATCH"; dns.opcode:!0; flow:to_server; sid:2; rev:1;)
--- /dev/null
+requires:
+ min-version: 5.0.0
+
+checks:
+ # Should have one event for sid 1.
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ # Should have one event for sid 2.
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+ # Should have 2 events total.
+ - filter:
+ count: 2
+ match:
+ event_type: alert