To complement bug-7241 tests.
--- /dev/null
+drop tcp any any -> any any (flow:established; app-layer-protocol:!tls; sid:1;)
+drop tcp any any -> any any (flow:established; app-layer-protocol:!tls; prefilter; sid:2;)
--- /dev/null
+requires:
+ min-version: 7.0
+ pcap: false
+
+args:
+ - --engine-analysis
+ - --simulate-ips
+
+checks:
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 1
+ app_proto: "unknown"
+ not-has-key: "prefilter"
+- filter:
+ filename: rules.json
+ count: 1
+ match:
+ id: 2
+ app_proto: "unknown"
+ prefilter.buffer: "packet"
+ prefilter.name: app-layer-protocol