From: Philippe Antoine Date: Mon, 26 Apr 2021 13:29:25 +0000 (+0200) Subject: Adds check for http.host.raw keyword on http2 traffic X-Git-Tag: suricata-6.0.4~88 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=a6d39deb00321377051d5d6d25af0e9ae2a0455c;p=thirdparty%2Fsuricata-verify.git Adds check for http.host.raw keyword on http2 traffic --- diff --git a/tests/http2-keywords2/test.rules b/tests/http2-keywords2/test.rules index 83cbe026e..da9cbe6c4 100644 --- a/tests/http2-keywords2/test.rules +++ b/tests/http2-keywords2/test.rules @@ -7,3 +7,4 @@ alert http2 any any -> any any (http.stat_code; content:"404"; sid:21;) alert http2 any any -> any any (http.server; content:"nghttpx"; sid:30;) alert http2 any any -> any any (http.method; content:"GET"; sid:31;) +alert http2 any any -> any any (http.host.raw; content:"nghttp2.org"; sid:32;) diff --git a/tests/http2-keywords2/test.yaml b/tests/http2-keywords2/test.yaml index b6f51bfab..d409e18aa 100644 --- a/tests/http2-keywords2/test.yaml +++ b/tests/http2-keywords2/test.yaml @@ -45,3 +45,8 @@ checks: match: event_type: alert alert.signature_id: 31 + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 32