We do not want to test number of alerts on every pseudo-packets
Ticket: 6578
-alert tls any any -> any any (msg:"tls app-proto"; sid:1000001; rev:1;)
+# do not test alert for every tls, as there can be additional pseudo-packets
+# alert tls any any -> any any (msg:"tls app-proto"; sid:1000001; rev:1;)
+alert tls any any -> any any (msg:"Stamus TLS"; tls_cert_issuer; content:"O=Stamus"; sid:1; rev:1;)
- --set flow.memcap-policy=drop-flow
checks:
- - filter:
- count: 97
- match:
- event_type: alert
- filter:
count: 1
match: