From: Jason Ish Date: Fri, 4 Sep 2020 16:03:47 +0000 (-0600) Subject: geneve-test: simple test of the geneve decoder X-Git-Tag: suricata-6.0.4~211 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=refs%2Fpull%2F372%2Fhead;p=thirdparty%2Fsuricata-verify.git geneve-test: simple test of the geneve decoder Just check the ICMP flow to see that decoding occurred. --- diff --git a/tests/geneve-decoder/input.pcap b/tests/geneve-decoder/input.pcap new file mode 100644 index 000000000..11800118b Binary files /dev/null and b/tests/geneve-decoder/input.pcap differ diff --git a/tests/geneve-decoder/test.yaml b/tests/geneve-decoder/test.yaml new file mode 100644 index 000000000..03776dc4d --- /dev/null +++ b/tests/geneve-decoder/test.yaml @@ -0,0 +1,26 @@ +requires: + min-version: 6.0 + +args: +- -k none + +checks: +- filter: + count: 1 + match: + dest_ip: 10.0.0.2 + event_type: flow + flow.age: 3 + flow.alerted: false + flow.bytes_toclient: 392 + flow.bytes_toserver: 392 + flow.pkts_toclient: 4 + flow.pkts_toserver: 4 + flow.reason: shutdown + flow.state: established + icmp_code: 0 + icmp_type: 8 + proto: ICMP + response_icmp_code: 0 + response_icmp_type: 0 + src_ip: 10.0.0.1