alert.signature: SMTP WILDCARD
alert.signature_id: 1
app_proto: smtp
- app_proto_tc: failed
dest_ip: 74.53.140.153
dest_port: 25
event_type: alert
count: 1
match:
app_proto: smtp
- app_proto_tc: failed
dest_ip: 74.53.140.153
dest_port: 25
event_type: flow
alert.signature: file_data smtp test
alert.signature_id: 1
app_proto: smtp
- app_proto_tc: failed
dest_ip: 1.2.190.250
dest_port: 25
email.attachment[0]: J.txt
alert.signature: file_data smtp test
alert.signature_id: 1
app_proto: smtp
- app_proto_tc: failed
dest_ip: 74.53.140.153
dest_port: 25
email.attachment[0]: NEWS.txt