being less verbose
Ticket: 7620
--- /dev/null
+# Description
+
+Test smb logging configuration options
+
+https://redmine.openinfosecfoundation.org/issues/7620
+
+Pcap reused
--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filename: eve.json
+ types:
+ - smb:
+ types: [create, file, rename, set_file_path_info]
\ No newline at end of file
--- /dev/null
+requires:
+ min-version: 8
+
+args:
+- --set stream.reassembly.depth=0
+- -k none
+
+pcap: ../smb2-01/smb2-peter.pcap
+
+checks:
+ - filter:
+ count: 108
+ match:
+ event_type: smb
+ - filter:
+ count: 57
+ match:
+ event_type: smb
+ smb.command: SMB2_COMMAND_CREATE
+ - filter:
+ count: 34
+ match:
+ event_type: smb
+ smb.command: SMB2_COMMAND_READ
+ - filter:
+ count: 17
+ match:
+ event_type: smb
+ smb.command: SMB2_COMMAND_WRITE
--- /dev/null
+# Description
+
+Test smb logging configuration options
+
+https://redmine.openinfosecfoundation.org/issues/7620
+
+Pcap reused
--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filename: eve.json
+ types:
+ - smb:
+ types: [tree_connect, negotiate, session_setup]
\ No newline at end of file
--- /dev/null
+requires:
+ min-version: 8
+
+args:
+- --set stream.reassembly.depth=0
+- -k none
+
+pcap: ../smb2-01/smb2-peter.pcap
+
+checks:
+ - filter:
+ count: 4
+ match:
+ event_type: smb
+ - filter:
+ count: 1
+ match:
+ event_type: smb
+ smb.command: SMB2_COMMAND_NEGOTIATE_PROTOCOL
+ - filter:
+ count: 2
+ match:
+ event_type: smb
+ smb.command: SMB2_COMMAND_SESSION_SETUP
+ - filter:
+ count: 1
+ match:
+ event_type: smb
+ smb.command: SMB2_COMMAND_TREE_CONNECT