From: Philippe Antoine Date: Thu, 6 Jul 2023 09:35:02 +0000 (+0200) Subject: Adds test about DCE decoding X-Git-Tag: suricata-6.0.14~21 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=d50a9f4c708bd7d45f2cdd104bc976ec49979bc7;p=thirdparty%2Fsuricata-verify.git Adds test about DCE decoding Ticket: #3637 --- diff --git a/tests/decode-dce/README.md b/tests/decode-dce/README.md new file mode 100644 index 000000000..ff3f3b1ba --- /dev/null +++ b/tests/decode-dce/README.md @@ -0,0 +1,8 @@ +# Description + +Test DCE decoder +See https://redmine.openinfosecfoundation.org/issues/3637 + +# PCAP + +The pcap comes from https://community.cisco.com/t5/switching/nexus-7000-using-data-center-ethernet-with-fabricpath-not/td-p/3341478 diff --git a/tests/decode-dce/input.pcap b/tests/decode-dce/input.pcap new file mode 100644 index 000000000..cd5577c8e Binary files /dev/null and b/tests/decode-dce/input.pcap differ diff --git a/tests/decode-dce/test.yaml b/tests/decode-dce/test.yaml new file mode 100644 index 000000000..dfefad3c1 --- /dev/null +++ b/tests/decode-dce/test.yaml @@ -0,0 +1,7 @@ +checks: + - filter: + count: 1 + match: + event_type: stats + - stats: + decoder.ipv6: 16