Add engine-analysis tests for like_ip_only rule type, to accompany rule
types documentation.
Related to
Task #7031
--- /dev/null
+# Like IP Only Rules (IP Only with negated addresses)
+alert tcp 192.168.0.0/16,10.0.0.0/8,172.16.0.0/12 any -> ![192.168.0.0/16,10.0.0.0/8,172.16.0.0/12] any (msg:"tcp, has negated IP address"; sid:304;)
+alert tcp [10.0.0.0/8,!10.10.10.10] any -> [10.0.0.0/8,!10.10.10.10] any (msg:"tcp, has negated IP address"; sid:305;)
--- /dev/null
+requires:
+ min-version: 7
+ pcap: false
+
+args:
+- --engine-analysis
+
+checks:
+ - filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 304
+ type: "like_ip_only"
+ - filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 305
+ type: "like_ip_only"