requires:
- min-version: 6
+ min-version: 7
args:
- -k none
count: 1
match:
event_type: flow
+ src_ip: 10.0.0.1
+ dest_ip: 10.0.0.2
+ proto: UDP
+ src_port: 52377
+ dest_port: 52464
- filter:
count: 1
match:
decoder.ethernet: 1
decoder.nsh: 1
decoder.ipv4: 1
- decoder.udp: 1
\ No newline at end of file
+ decoder.udp: 1
requires:
- min-version: 6
+ min-version: 7
args:
- -k none
count: 1
match:
event_type: flow
+ src_ip: 10.0.0.1
+ dest_ip: 10.0.0.2
+ proto: UDP
+ src_port: 52377
+ dest_port: 52464
- filter:
count: 1
match:
decoder.ethernet: 1
decoder.nsh: 1
decoder.ipv4: 1
- decoder.udp: 1
\ No newline at end of file
+ decoder.udp: 1