To accompany rule types documentation.
Related to
Task #7031
--- /dev/null
+# IP Only Rules
+alert tcp-stream any any -> any any (msg:"tcp-stream, no content"; sid:101;)
+alert tcp-pkt [192.168.0.0/16,10.0.0.0/8,172.16.0.0/12] any -> any any (msg:"tcp-pkt, no content"; sid:201;)
+alert ip any any -> any any (hostbits:set,myflow2; sid:1505;)
--- /dev/null
+requires:
+ min-version: 7
+ pcap: false
+
+args:
+- --engine-analysis
+
+checks:
+ - filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 101
+ type: ip_only
+ - filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 201
+ type: ip_only
+ - filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 1505
+ type: ip_only