From: Sascha Steinbiss Date: Sun, 8 Nov 2020 17:34:49 +0000 (+0100) Subject: tests/mac-eve-packet: check packet context metadata X-Git-Tag: suricata-6.0.4~212 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=08cecc16c085e95a2df8d036086afa728f634d17;p=thirdparty%2Fsuricata-verify.git tests/mac-eve-packet: check packet context metadata This refers to Redmine bug #4109. --- diff --git a/tests/mac-eve-packet/suricata.yaml b/tests/mac-eve-packet/suricata.yaml new file mode 100644 index 000000000..56c9cc6de --- /dev/null +++ b/tests/mac-eve-packet/suricata.yaml @@ -0,0 +1,11 @@ +%YAML 1.1 +--- + +outputs: + - eve-log: + enabled: yes + filetype: regular + filename: eve.json + ethernet: yes + types: + - alert diff --git a/tests/mac-eve-packet/test.pcap b/tests/mac-eve-packet/test.pcap new file mode 100644 index 000000000..0f19a2e75 Binary files /dev/null and b/tests/mac-eve-packet/test.pcap differ diff --git a/tests/mac-eve-packet/test.rules b/tests/mac-eve-packet/test.rules new file mode 100644 index 000000000..41725c36f --- /dev/null +++ b/tests/mac-eve-packet/test.rules @@ -0,0 +1 @@ +alert ip any any -> any any (msg:"test"; sid:1;) diff --git a/tests/mac-eve-packet/test.yaml b/tests/mac-eve-packet/test.yaml new file mode 100644 index 000000000..59db8baeb --- /dev/null +++ b/tests/mac-eve-packet/test.yaml @@ -0,0 +1,13 @@ +requires: + min-version: 6.0.0 + +args: + - -k none + +checks: + - filter: + count: 2 + match: + event_type: alert + ether.dest_mac: 00:25:90:e3:d2:e1 + ether.src_mac: 0c:86:10:ed:d7:c6