From: Jeff Lucovsky Date: Tue, 12 Jul 2022 13:18:09 +0000 (-0400) Subject: test/event: Test for reassembly depth reached event X-Git-Tag: suricata-6.0.8~27 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=cce4ea566d8d971352562ab26c9dfc3552f814cc;p=thirdparty%2Fsuricata-verify.git test/event: Test for reassembly depth reached event Issue: 3512 This commit adds a test to validate that the stream reassembly depth event fire. --- diff --git a/tests/stream-depth-reached-event/input.pcap b/tests/stream-depth-reached-event/input.pcap new file mode 100644 index 000000000..49c711601 Binary files /dev/null and b/tests/stream-depth-reached-event/input.pcap differ diff --git a/tests/stream-depth-reached-event/test.rules b/tests/stream-depth-reached-event/test.rules new file mode 100644 index 000000000..af8bae2f3 --- /dev/null +++ b/tests/stream-depth-reached-event/test.rules @@ -0,0 +1 @@ +alert tcp any any -> any any (msg:"SURICATA STREAM reassembly depth reached"; stream-event:reassembly_depth_reached; classtype:protocol-command-decode; sid:2210062; rev:1;) diff --git a/tests/stream-depth-reached-event/test.yaml b/tests/stream-depth-reached-event/test.yaml new file mode 100644 index 000000000..2a293f455 --- /dev/null +++ b/tests/stream-depth-reached-event/test.yaml @@ -0,0 +1,18 @@ +requires: + min-version: 7 + +args: +- --set stream.reassembly.depth=50 --set outputs.1.eve-log.types.2.anomaly.types.stream=yes + +checks: + - filter: + count: 2 + match: + event_type: anomaly + anomaly.event: stream.reassembly_depth_reached + + - filter: + count: 2 + match: + event_type: alert + alert.signature_id: 2210062