requires:
- min-version: 8
+ min-version: 7
args:
- --set app-layer.protocols.dns.tcp.detection-ports.dp=1053
checks:
- filter:
+ requires:
+ min-version: 8
count: 1
match:
pcap_cnt: 8
dns.queries[0].rrname.__len: 1025
dns.queries[0].rrname_truncated: true
- filter:
+ requires:
+ lt-version: 8
+ count: 1500
+ match:
+ pcap_cnt: 8
+ event_type: dns
+ dns.rrname.__len: 1025
+ dns.rrname_truncated: true
+ - filter:
+ requires:
+ min-version: 8
count: 1
match:
pcap_cnt: 9
event_type: alert
alert.signature_id: 224008
dns.queries[0].rrname_truncated: true
+ - filter:
+ requires:
+ lt-version: 8
+ count: 1
+ match:
+ pcap_cnt: 9
+ event_type: alert
+ alert.signature_id: 224008
+ dns.query[0].rrname_truncated: true