From: Philippe Antoine Date: Mon, 4 Jul 2022 12:36:57 +0000 (+0200) Subject: dhcp: adds test about leasetime keyword X-Git-Tag: suricata-6.0.8~36 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=242310b4d1a2913c35e95fa40d93045157c439cf;p=thirdparty%2Fsuricata-verify.git dhcp: adds test about leasetime keyword --- diff --git a/tests/dhcp-eve-extended/min7.rules b/tests/dhcp-eve-extended/min7.rules new file mode 100644 index 000000000..841a842fe --- /dev/null +++ b/tests/dhcp-eve-extended/min7.rules @@ -0,0 +1 @@ +alert dhcp any any -> any any (msg:"small DHCP lease time (<2hours)"; dhcp.leasetime:<7200; sid:1; rev:1;) diff --git a/tests/dhcp-eve-extended/suricata.yaml b/tests/dhcp-eve-extended/suricata.yaml index 7f2fafa63..cba2138a3 100644 --- a/tests/dhcp-eve-extended/suricata.yaml +++ b/tests/dhcp-eve-extended/suricata.yaml @@ -6,6 +6,7 @@ outputs: enabled: true filename: eve.json types: + - alert - dhcp: extended: true - flow diff --git a/tests/dhcp-eve-extended/test.yaml b/tests/dhcp-eve-extended/test.yaml index 68644dc01..58782b34e 100644 --- a/tests/dhcp-eve-extended/test.yaml +++ b/tests/dhcp-eve-extended/test.yaml @@ -57,7 +57,6 @@ checks: dest_port: 67 event_type: flow flow.age: 0 - flow.alerted: false flow.bytes_toclient: 350 flow.bytes_toserver: 342 flow.pkts_toclient: 1 @@ -67,3 +66,9 @@ checks: proto: UDP src_ip: 10.16.1.4 src_port: 68 +- filter: + min-version: 7 + count: 1 + match: + event_type: alert + alert.signature_id: 1