--- /dev/null
+## Description
+Rule test for tcp-seq keyword engine-analysis output; includes the test.yaml and test.rules files.
\ No newline at end of file
--- /dev/null
+alert tcp any any -> any any (msg:"Testing seq"; seq:624; sid:1;)
+alert tcp any any -> any any (msg:"Testing seq"; seq:723833; sid:2;)
\ No newline at end of file
--- /dev/null
+requires:
+ min-version: 8.0
+ pcap: false
+
+args:
+ - --engine-analysis
+
+checks:
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ lists.packet.matches[0].name: "tcp.seq"
+ lists.packet.matches[0].seq.number: 624
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 2
+ lists.packet.matches[0].seq.number: 723833
\ No newline at end of file