Issue: 5761
This commit adds tests for decode counters which are new
- decode.arp
- decode.unknown_ethertype
--- /dev/null
+alert udp any any -> any any (content:"data|0a 0a|"; startswith; endswith; sid:1;)
--- /dev/null
+requires:
+ min-version: 7
+
+args:
+- -k none
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: stats
+ - stats:
+ decoder.ethernet: 1
+ decoder.arp: 1
--- /dev/null
+alert udp any any -> any any (content:"data|0a 0a|"; startswith; endswith; sid:1;)
--- /dev/null
+requires:
+ min-version: 7
+
+args:
+- -k none
+
+checks:
+ - filter:
+ count: 1
+ match:
+ event_type: stats
+ - stats:
+ decoder.ethernet: 1
+ decoder.unknown_ethertype: 1