From 0f3e7761da5904baf6a2e04a8f1dcd83d686aa71 Mon Sep 17 00:00:00 2001 From: Shivani Bhardwaj Date: Mon, 27 Feb 2023 18:47:16 +0530 Subject: [PATCH] doc: add dataset examples --- .../dataset-examples/detect-unique-tlds.png | Bin 0 -> 28362 bytes doc/userguide/rules/datasets.rst | 25 ++++++++++++++++++ 2 files changed, 25 insertions(+) create mode 100644 doc/userguide/rules/dataset-examples/detect-unique-tlds.png diff --git a/doc/userguide/rules/dataset-examples/detect-unique-tlds.png b/doc/userguide/rules/dataset-examples/detect-unique-tlds.png new file mode 100644 index 0000000000000000000000000000000000000000..78b862f36e2deb40d7813ef36548d6b38edc4db7 GIT binary patch literal 28362 zc-ri{byQW+`YyZ;KoA541W^GgrMpW&z)d&Oxq(f0m!yKUfHX+Aw19w$NH-g#LAs?I zzPa$6-#O>|?zsQmJH9^-4#!w~t+{5s@B6&ZGv{1y733swut>0AFc=Q}f2dijG+Iuf9 z9YO@J}kLcfQiO(+l+nbv9uU15He) zHPd0M8VJ(%;ZK4|)Qa9eZXhWN3X@wvc-t5DX-2JQ~8&xOfWWyS z=oRO=I_CT}&Cj3gJwqic4q@-#OA0^{S=clj_Aj-G;dS#lR`$0NJFqPo&$my;++NgnYo{v=$}TK! z{F(UhWW9WCc+z>=NWPOM$oqq4g>~~H9D^>!ezkv4PI#{CHmW2*%eujRe8Xkp`0d!k z;pr(KUrqPSII^s>?+0&5OtnslDQc5dTCu;{Kg0ZyBnHc=D%{R%u29f~@Y{2Zv(I1_iNH}5BQ7~FOqJ}#e^Fy7~l=i!t=#ECW8 z%E^A1|Hf`Tb2Mki8LvmnoGzm-c6(tfeEf0crmMTApbpWOU+;FsEHc7&YG2JE(zQ2f z-IO-@trmIKXsy+kd_6?&Qj+hF7N#bUphZYJ*2a)MY#)298a-v(B^SjJ&rfPB3=3BY zpHFfTE^g)yaA+O*DI+DeJyQL}aO2IjnYV#Gr1N{cVN#50$xKW*NtRE@1yfDz>1VRh za&n8NMhEd^wT1%Vy@vg~ud6DU8pcSm9wz9X;e0^g4nVmCWsr@V$HMf9i0nbzL7=if;nKm9t^D2fgd0 zakhnbDk^Dj%kxBCJ2-VfyPNHCzVQ&(GTlMXY*Y`Du_^MK*tCT%6nYs2K zt#zTR&NdLVY2otpJh2!&t|@LH*)yM2_>iE8gI7_7jrP3o^N}l7Ix`;A>jeo)V#AkF z3LiaZV%O0gE@L~>e52tE8gyb;CF?)<+N#iMNqW=M$p2Yc91-j4Xet?!I4>}OQKBOH z1;(Vj0VVyYBN;{4q)w74{)y89d*3*_beXZ%mlQ#Uly1U8+1<2uYaRZsy4yQ1gBMDq z{E-eT1}kdhPag|Ma;M_HNePzn zM*lmjLe|Q@H$FXz!neaKgz~G`%Kc$QCHjeEjIbd4H{>_II~*juZ+VGsKxNb)ZnE9? zT3hb;Zry^PAhE9hcR?1E#^}08&XYU6+{CxOS`m(@D;iGamC)74C9MQ~W7_&?k6ABu zWUW8e;GH{1nsL(>hKQKZHDO>AJS@zvUxA^2o12l37j+rL{RCV0>TKCaEZVjI zkiVYpfe@9k4tl2NWxgx?sQp-U(Y-60Q^ekH=1$EMbQX<$B+u4@TnxRmq8Pae7g1#b zyeFRFxBN4eq&RB0eQ~d?)zI^Mzg(KzXPM@ZuiuwnvybhMyv=cc{O3}87QaxKSQ;-C z{`6CEno{Ki5s8f{nz!T6NGjV&YcLmCQjdNGf$oeU z?90ZaJv3*XE5H3p`E94bbs6fTZ^_Gc7UM&tW_mYGR#*q@Yd;;j4mFDecDmAa36Q_} zeW!!c(*Je56CRb>(!0BN#^qzs>a2Y#$J0oW{PV>A3TK~%;aIb{~lkZ`}^aiUY`$4IQsNO;>KwOAY=hZF);UQzrn zo1Z`W*_0DPL5RVBM8c->^mZejWU=U7x&X}#Rg4&Ey}qm`a63B!?b~;R?ib!+>Z#-V zjO90T;|Hn*-Y+h7rl(|fckY{=aAW<}+$R6?yx0#WRbkf>t&`eaWn@g%TEf+D5x=-K zw;Z2<=z=RCS~jOjz02w??1vv zlf|(~$$z3nS<}y3?1X||hwG&4IwfxzwdSY6zM0NQ*_?E8>MzFZnJb4rx+XaOwZ%zU z`M|gHar#z!r0i&{A4j0}9arH@n+{k*&GV7O5iKLKT-@g&by5>BjNq>?Q_DxZrY1+n z#+yt@&d*^{WcC$}65^i#S0+IMPW(z%hR?{xipjv(#t^~eYGn(9{se?wZ4Hbp5RT-A z2velBAjMXF69qZaSdc=UQ6Rt#Z=eCckFP<#s;x(oa7Qzy6{XR@(3WoG5&R|nkCMDsr3jZ+$rbsK>tG7V+|D&WM(!}I{-8bmTRp->s2Y(?*0kzL(Y-5Bp=DWJ&HbxlnupkhOtXyo|j2t|?tc->nCdP~$>|9(d zY}_VXhU~`wRu$aZ!O_6l2mw_E?l2)iJqQjX7H$?^Hb!Gm86yXau@R$z0XsLNArCu` zF&D29JA%#V->Q(eM*^=ju>AL4K~))ps<=%ISlL(&c^O#@+1VL63|I{qc?^s>8Cf|w zxsABkcsN;kc(1B5HsX`8v9~e+=0sW~=P3Ea>=6czHufquHkN`EP!;6Rn^*2lF7S66ULqYp3Ad|Te|=sV zVfXjf-=CJqzdy*Y+?LP4=x-wq2F{4T7Wtn?MrH=qrU($<%>Q{G`M)q0D>uS~lM}(t z$jQSA?9Gb+cH#m-2u#IdV$90QX3SyqpS3vHm^iu^*ds(t!AQYqfY)4&hWy#pRMP%u zX%{mDG*2vS?2IgIjBMO0tUP>d?0jq-^emiwVCIK}9VfB5gejr_Nf|2Fd9M*iE#e;fI4Bmci@1nXad2Vo6ZkPDDAF56zT zKnkH7N=v?gT|)oT8**d79ZcJo8V)enZG7neHCSRYF}R802$vPdSi1fYo0HfND`N%* zBZt9Xh^V-ZtxvkRh8;5b+fF>M3LXwtUnQ@G-R#Xls8Oj6-K9;ZBiWc z3Kf^`Ttrf39-H`9_RR~5^4(Mabfa{cXi>LKz{4`)fEf=O_9G3P5j7jU0r;Y!Ml0w>gofg zANk*h>>_wK|5irx|C7oru15DYS!Z=b9y2P6;QCj54L+W{uk-B*C%k`)u~>iy9g~?D zfv`U>YD{{2_Ih7u82sPr;98gCr!u>@e6CDN{Bi+nT~%h2cOsN4I(k->reoPLVa)Ak zj5Yh6oBZ~bRVs=uTCvQ()9Xrk+Zls7TcA2*v~yfXNYf&pU7j0gep;x;szWGuD~+PQ zgj8s!6fMNX;F7}rusP*#6%32AnkANfcN z?YZgu$y7`B?emwB{Pqy{*IXEUNd1Uc85W5-W8*jmQ~s*Y?Qaznv|2p!D6mvTRYcJ1^HW!P@*Oq0=o?pGDWg|gp-B`D<9 zm0)3o_rI=)BDewd@(B&m&6c0k=Ci}&s|#~KN3Z$Hbc}U~l5yG%cI|)rSDD8=METci zEAol)#cn*$QL9jK4x9`f34AE?2nRA9R?KZb=X3mw#Ow+O6Bv0+#ivM;_bvlDl(T=U zxC^Q{_n?+S2yXDQ!y?gCm=^QqL=I^opV6m~VY*fKnDl8)G6Od@Ohe>Co2$SZJYBQGl~lJJ#=<};xuQGeg^YeW0L z8JKLbwGK-KdQIL0;N_VIP_aMnttacUm2>4DG)BC8HCKxrxl@M&+0qNk%Xv0U=LZSlj7&^&{LbqvkD9xa zxYO2ZNd?_iZWA%7xVpL~jxlRh%UFz*c&%@5OxCL#7#IYNUtFBp=+xQ=h7!3RvEL&m z&RbqK3%Ld}c>_k_n~O(6Qn0hoX)*gfFghzB;O6ns(Q+trqr(0w3V}rCYgCvB9%2+x zOULDbuAiK4HHBGkp$g+yhl?$aYRpju1T|nZDhdh;A%|`r9`rOc5`($&>V}5DmC44Z zeJ+dnoK}g$GmwKhz5Ck!ettu>4yLkcLV~gzr8@OF*U_-D+%J2DFN;7;`5uRx(OJ#G zxP_vDSOq%uTtqD7E4gXjN}y|;&g-xK)#tt@AD_U0fMuV{(=;mNSS50-)*%-imy|(L zQnJc&RLNy?qCb(-B6ZEK@pO})mzQ_t{BWAPPB0&%?{`ZmAs$}(Vt3NhaV`o9(bUvb zI+eW0DUYoNCT%I$3v}Zjh=2+(~UaUu3alHE9;-EcLDRwWi_T! z`ei31M>Z+v*RNj$#Y`M-q4G^&2-hjoa{4^OeMbkz%Nv)_*BR&#$eWc12Wp99lo-wSQqX zR;hTfKB{b~TxG5b%+lH3PCM##`#wWou~v<-jZNu7XZ+gtz}xL(0=;&cT3Ut98)G{M z2XWa8yG^m5%F72Z$UM_KiApyr&RF6t?7|;5&u-4tZm>AsKaR==G(V# zQ`69_{wg!--9OrDJT0M9Eik^ta}DOI3B_1ee_IqKHC(68F^Wnykpq6XImzzH42K3A z92|UcG>1Fc=yjSvx)iVH9Yxh}yqF~4U?nQ*mm`xvK}19Zy|TT%oydleDtBhotc;9_ ziBT(hm64a1N2FN;T)gGS4}oggfj{N3^y(y&r1*Z z+`XI85=taoJ^Ahd`}+?c^3;kovpeTV1zZ(^?>rtjKRx8dg!!6^0)%)@0@*3r*wpmt z$~UUk2ybS1TwI*{R>L6y=uftEywKp>*}=F?d3Ckg`N@8o`*@Yb$m;rN1(>zWI>!|X zb#-+R{_+_a84??h9z7Z=P^AwH3`BxSVy?6X)?&x9P*MWc=jG?O*chvl5No(NULu>U zbCL!(?^G3^<^gT<2-l_4c)6x=~V5lt&*Ue>Ox0s*qC7Nr$XRl^eik2Q0G9iY3=}N zE_I`aG9__GM@RDkq+#LW%5OKDyJH(khb}KKKRw`s=B6ctknsL}6As6pV`G}pj;9A3 zDoeQTL;1?N97aE}ppdYrklAgQRjZXKcZTq&HGr$^VR9$mV8+^gb4rz zHz(^KE*71X0xZn~P-Jgs7nPfvi$%o5U}|cLDpc=fDN>9Ea7G2(H$~7xEqZ=&kp^6k zj*XENzj0X|q6OI5*3u##c$+9LDJiKywJ=A};~?wk2=rcc`*(|Kp28D1clUxs~m=nZzpa8khnUtbuiNJAMoOB~hy=A@RInpz^ClX*FL%lNn!8Wurc5YEF?56q*z z$h~CTM?CtUi&gTKI?{xj{QUh<0EZ_*jw(BS1&DF~&2fAh85Zo78v|M+B|6k_hs7@V z_63>Gnc`?Ug1u6@J($cpPdxN~zTMo{}5Fz*Q@o_qH zq?Iy61NRn_Y*s-E)2y~k*iM2;OE+9zoQ8yjc`X`PuH?IJ|Bfcb#*j8dAhN-DJ9>KL zyuH15_V$J($-Lg1Z=ug1R{Jvi*Vor8joYJ*Vz5q+;#Q&SwXb>(1{tJZY1*5bDD2a?Gv7`L2PP<3>`g0m+g*I% zj_bYMLR9Cl6b=mz_>jeXTT~*iLk@89%$^kfrylDuPvy;r@)XDFT}m4-PAoP+>r+!x z&@1pSG%%PhHsm3?z6TrQogj|@kWn%;G)%0yjfojW1!7wmH8=UiO&JUc1Z_M>g+`8g zX+mC9f**vJnsk5sVF6gisQtO`&lYGdBqW5b&I+WdknnJ>F{TyXrzrBb5fKpp^U{Zl zwdm>Sq}WZmpwzDle6CodA}AE+0gZZzw)tpzHU$O6{L+%CoVx66FpMW~08L7X;nZwwN`-30(G3j^=r|hH6cfOK0w{?y{S?OyjyzHaj#O#bf~8aMEGr$y&|joc;W*!Rm(yZc24Ef6DjM1s z8333uX=!ODy{W~if*w-QC3;OIkk0}_^uDIXCGi0N!GnBYLlXD<)HvNzofEGH{AXym zxYPi!N$>tx2K<7y(HV|QlY|a4mW8t07jnQAhCpb7l%2Fl{tPKPn&l=k(9zjRkE*q0 zU|`_T|LWUHx&#O!C{b8u)G9RM;B05tU!qh0PUwsC+OTYm&GazHu_lf(rHv;A{nd7M zb`qQ~-`3aHpB!$LLhd>!FN^|q;J54H#L+_wT>U#-|&-v_O^`2_d9UwSXUG!B8zN3$>~81HIFOd&W0m#!T2aH()bp zZl@bH3-j|?g!F0xcBmpMxPw<#>rOus)#&8`<&pl6;!-bPx^AAM@)X5@I|uoUR+z?z zg@yH7Ijs&wWoK`XM`n@Usx8(h^|ohTbvF$oq(U-8`vKz-sDGB_ER^pqQW0NevB$dNQ2l=0G_G@oGtZpSYcry z)e49N<_(_R#qL6hFcKtifU#<;BmhkDPxhtUdjN*W?P5%48CX|WS8Ln0u|QA<_)3*= z`#se{HCYfXic38yX~gEFJhsn)D=K75#d7#uc+QQ?2a8cF?@sq|AwP@&|0EMZdGqr4g5@1M4otqUY-@yI7Ht{8(tRfFXL@>indHxa|2JJ;)MF7m)8`0o zvnXvaIbu01k8l9}+u7ge#PSmr6`kMOD!oT7wH(Gh<(kn7P@n8ETeU$mddttBtHm`_ zQp4VW6xKPd#R&)ss+JqWnYfHUoE`5Lf~352c*rf&bCCuAn0-msvp>!2^)WNk>FCca zL5-cQZ6uXWgFEVz-v=r}TBR2tzYT-`m6oGy4Tn=6L8rfe|K{*Iaopb+kB>ov>4!sz zmF2#_x)Q6d+Ydb5ad%O+8KVXu;tE9B0oFovxS1s%_?gtnC1PGLu4dX>i`Rbsih9gN z2$Kj|dLK@@kg%J)+ga)@rB^Qz7;FTI88H0Tr`6K#J%GS+PgJ|@n#d;eD1y$Y0Z#q? zsXVE;xHz&mRdB4)tG*o3nFGleJJPuLw^MDj4jr56dP_b@h%`OGXP~)iYkLWDvIsDn z*Ke*^I@M@@e}6#y^MP>+L9)XF3?}l47~l^V1U0l;)kRR!y-O*v3`G|R&!Gkn7l>Z{ z`ed*=R#jN%vQ+|@FvO+nT(>{c$R=h1U|5Zj7h=s%BZNKw2`R}LwDQWzA)q#L0ev)U zkETA^8zbIHRQ=*=mm=h)NyMbB0I*uG!)|PRybyE}N-^G-=PqJ4 zepz!eSV5^RnK3VNX@H6e#wCjbzN;9KE-!TaVx&|rzNx9nfOj)%&Z_@ophWnid@Mq` z4@11U-1Z&iQl-sVX(N~Dbh1fYu>dmwuEga`Js>(4VVKK$9vE)h$jAuZO{c9X9SF7r1O%eJcq~9>`58f0y1zD3=(07%yw9`L zo5l=WUJP#!sNq7n6h1nothU=;>wxV5;+_YbNWvkBfZ>%wV`F1<))TQHvx(1kV>LEu z9dV4EbOvpB7Q;n~#>QF6DJfyoDgawRG}gKA7l5I}S=QfY)O6}YHag$aX0n_1n03Z60{f-{p^^neEAb{7U}?}y zfnH5E`RIYPq+G07_3rxwNYsUnD+8dQO8H!oa&9=NT?G(7IWCy7;uZeuL!$?xGul1)0U{= z<>AR169V|uJ|^7J-7RZ1UM;(S0YqqaosE{(c>E4KF074*feaV+Rk|-j3ZQZD!e``gI`xud02Xo9t)oEu$1-T_loi_QGn2)|`VIds9u3TQZsKqv zPbfCV93l;2&uPT3mY&FELp@Phr+Lgn)4okp>)~Q^Peqy5gs4U(9k>@n(ETt8VD}ySb>P3SEPFl3L zV8#?s<1^VLWBGRs@FLOXdsD>lg^(ZhMl6SSrnwdHU~N>8Li;Mcuc_$rot!+hZ7o^{ z|C9?A)Xl%Y%jN?$1iNZz<(9v1Q8RV0f8)luO8vp+NOGFG5+01j4r+m13=jR9hGfsW zbK)O6{By6p&pGFnDj-=CpuuDap!eHYKo5s!=k*J>$&Qx+(N7dGx@&+3`|u26xse%H zwSVi8FmmS{s49%-^zQJarlL|HfU&R+zX$VVTq)U{K6|6C&~n9)0BxlJ6`ZzaeI$sr z{m7n&H!D9yhs(liH1l<1Dp`6dO?Q8vw+_OpyY&u?g^*@HBsr2?V?YuUR!$%-tvemX z6(HgowHY)$ctWc~`$IaqdrXQ_sHo6Rc&jfDvx3u5-vv=omcatk$J*+ZUD4m12#t|; zzR-lhG~P-(TTIpxNj{0B!N$K)e#e5I9%o~o5u@-G&O?43#eP<3yuNTWk#7ce_D&SH zL>C=4#yDk9w%yI=~Jn}f0g zg|-xw-BOA;jtcWbzL1G4!pQv-R95XdmK&v9f7z);B7gk+2`PsioywPGWn~hFI(3e4 zAge~!c^&p9v*6~a0zx!tQxNY_6%`eL?$8Ed($5;?W{MoD?!Tnortj`J3vmk!OBT!K++LyH!=X@m)hCrwkB^?j&Ko==aQe zLY&Bf7bQ$gShsHvZWXH0^6gLP4`YRp>Zl1xwP~`dyJ%V$`s6Yd7{5;`Pjz!XMKq z*Hu!{GBL>wns%k@uPl2H`IjsxDk?I_TKv{MwC~H-V&!vSOf;OyXO+Qj)2!nv%vwbV z4Eg+U!K%fV5P^|X3biJ7yzbH_E0WvSMi^Or17q*cQ>5G&ZP0?Cvzh@~AK~;ovTZ&* zJ=n<9XOZR_zQ3x{tI9rtp^Pnn4+6rK5TM*?}fOFj9o$_xt>GDJhHp!Ma+dY8`O9yy$c9Ff`C*&jcC1cEE0H8mLM z*FqqL44p=Vgbd`!CK&^H3^;D*=qN9$8c3$G29KJe;$pzx zGmXWv0ZixW_*~@Uw?@#jvMPcctlFK(3Aj^6u22ckN~?eX7pN5{0K9fk_l+RW>H~9;852E+6*~k0nCugC|kS?jMuV3r?=1*Jw zfJNW8dh6E{X=&-lLXI!pcIM&3CO|f??zTUT&eBsaQK>RVv28Re?`{NOj+Hs&QXxSw z6sT6@^q+5UZ@V{%VLTReR{{584pRlotEx~zVGmIt+qI@*n3|fVoGqm}3O7X^Zar*t zwsSifw#S>_wi5Q3Hk6Vmd)m?erBSt^-TuOCG_#Dj&PHWwE zbAqrR7XXl=sqg*yQv&E>6ex~upk--Ul-PKj^LuVCY+9z;%3|+)RxCJ`&o_b9D5x=w zO&l;c&brC(-$lEVI0w0>Ju{PeFNKRPKFgD(@H$BNHy(*@jMt2OeSM?KZjdI^N-~Tj z+dwS1Kr({VvYlL{ovpVrKFDdC2K#IUQN_i@RJ3|iU+5IlpNCvpT3TY09q0vsFnrMH9hb_T zEgj3Y_gS;vTBm#|nF@sM+QpGrv`T{}XC|K6`mZt)A_y#&QKfKX{rDgnWiZMw||dGC+}ydoEvb&obt;a!b zlBfNTwy2Yx!cxb>O&!1v^F;j7%_r-s0MW|%@#96YW`pLm%!f!r944K*tVKpmv$-5u z$j?@XN{UBxJ-TgmCBjLvIW30&j7umrYIBi{_lwP`>yDIqh|=Cl<;P}QGBA9|Wv#Nt zWi_vn7g?ZETtK0#TcFlZ2l4^u=vD|&XZfmY!$d-F)pAWL%|1uQPr6ju~R8bpLr4;43}BO<1`(p5uXLC3;sA!{vEK z;%I%k6cNib^_&+8HM5nl(yK#D#JDbfRo7H zTfJD<>Zop;lGB5vShM;)RbXHst^Rm5!8kCuSVjh}(5o6x?aK=NI)M1hgOPds!@Hqlb$$GUr+&AYDFoIijc8=vg~lqLCTf zbY^(#caB_AToFbDmDk1b5>Tj+W>sU*D{*sJGXLs(jfBnk4FtZ{I%GvXd*fS87K6>H zTp+QIeL=>6zRN?~Ee3k^muG{vx-J_N$0{OyJv#N+2CCUov6U{pq{kO$6*(7w{GBbQ zOF)AZ^76gLf`QQt2fNA&3Xyz{%jq{x4=sRX8T)MDzu1*(MO<=l{+{-%+AYuV8h`h? zj>5&M7^nUPA_Z|BiH9y28xU}Fe`{I~S|$N(ns!BmcyoQd=i-OI z+d%SXJPdNVOp?gs68=^GrD&lfAB`$0(-CDr}Fg2yHe9Ma;&;m0of%8zxoyA3A zpeh_g(BFG?E?+adVy)sh9_7+Q%{c8O2_}@5havp>YnEkJlkUW9YUy~X=sK6RoVnKU zl~S)$DCZ;!xRnD0+#AvJLH_>nw!K>CXtx(y`jChq$!5=$r+>zx;IlEF%jdNEGMdYJ z%$V2@=Zht$?!H3Pp}EDcqX&H6tB(LB>UwmuD$P-Zu{BNkkj$UMX+zd+p#t^$B5>bX z)wCiR|Jf+!r%IJ(bew23N_e#}w#rzgHRH-R*9$Q8@t!ZxT_Ck;v3-G!50lj(t z`g*UUCD4(HM;kTmG&ylud{q_?8yks@&qf-ub^&f9hbopJi|=?J%~Byh7`WGiMCQCP zMh!2}Yicz3y>@ADZyy~TEE#ebORp~HuY~#5Tu{kBo&4ha@iThq+YLG>jnGq~ICUW{ zSsf4MNgr&b&h4ck?*TNdo8Qw3UWki7a3^jYX>4db+mUYGx(^24FkX`4E}V?NWvVxA zEcOHBZD<31f4RT;k4Gu!G30!Y9+P#ASIrs7>yT5b&?d;+cr+E*Dc@JXhPl4hJu>c> zMki3SeU)q-+`3{mju&~&sCZBRr8MvpXXDab(R|TL##ZTPmBn+nJv+^6%lvbUJI?@_)T*}Z2LuRdM)b)l$>5h#p=3~CijddX zpC{=`Eg{VFV@{5aGES(WVelKVZZBO4CI_8jFcbRoew>eRpnV0u$bToU5 zWdJ(25mc<|`IBV9v#V<6;M0h<6eo+zHs;%%X|fzNE$hN`EiSJe6Vg~lV`lZI7PSkN zInP~lSe_NilQ$SG$u+N?x8ep%U5-FI>z|KY37OSoKoXK@E_wXu(a=fMG(OyZzAa-Q zTiW9C;v5UpfY!!1xk*kJwKX1&oHu1Chrtr~ZbehoB;!u~iuY`hv$9wm7`5n6EE9TF zco1lw{6L-{B};B&th}aX1jI#^+pdXNdb!026W}>{z~ppFS#MT{i%-eVZr$qpWYA0{ z_`&w@XnPLV&!1p1y}jtvJ35L|!fbc38w(Rt(be@cpjyfs2|Ia!33zeYrhm-LTmZOT z+H^vvkwhsOk#mBs6`doSVovZmYfr*!Z@E93bZ;?%%gH<>Mv+X|Tbs=1%&y?{*n7tq zQoRHIU(EsA2nh>A0ipN+O{9>lM{NH0?~ip;Q$gc4Q(urre7!zF0S(w(5jS7J9ayO` z@7#%_3JeM=KsD++=ZC_%ezjzo#{RFF5!YPmn2v(V5$N zbWZWF;!+H+tb5{u&|1j>`EpZ8-MG0@y!sv>lKY8vihxLd*bnGGI5;TKDU9Q?oXGRF z8YdtlW2UF4-*DymQgF~bOAR>YAkZ65KqlxkxT}Kfp#HVmN=ioNePEz?NX%W+VJ~5L zwdLqL(boY10UX87<*wU?8>1DH(Hw?9-WczGdpST)N?HJd!$39f{nX3c#b0Gcz+g#$ z$}NC-5^rqm0PqlEH90v+cFLnG9!kRw${L z|K;+{?qS>|b2dV_*y8&7`oIu=F7W+cfyzz0-=z6bv78MGxb5!gkB0Gs*Hua z%6M519d7wYe_s=D+YuN%h*-k*pzG{>xDWF`spRmv82g?&H zcItnbff_*S?cKe=0OUcSfpF-R#U&*zX1=}#uWJDh*?)<+an(`09t zwuEJ(fmjb{-plQD(3cW7UK|P+IwLCmaG#dkxpRl>rpAMB?=9Y=emtcz2R(KwS`)n$ zK(zR4)Z&DCCZKV7oK{*$cqy5e`mO4%C`8eelaw?U>EI8=^INZBGt_Kvg>kA1;-s16 zhIgiI8hxUAfi^b~ody;sj??qmN2vp6HZ)TQriBjx;<>l9IT@5n8u3s!R^u=w`q!^l zUI(M5QZHXd=H}*}c<;OwS{alK#3GEQl1=7-$1~|jRZoJM!lt*tA!d0VNLDS6J7P1T z0FC+l#A$SF%>3f)xInYYyiSkO+1c5AAnPp^a{OSU&ilNM%W8@N9(0^Qy0Ef>d^I4L z|5VYOf|62ib^qdL^9dCd6>(6tV6kNIH^H@SB1X+2mihIF{k53lPcc!P9p-0;!R;;W zn#BbRABkO`gr_v*u->jQUE%cu+KLul=XqTIU1_C-7#}~=uqCumZDVY##)gatU1m7M z7yrbowJC8AA-vGLBq0LLQi9O;2G5B~+cm3}p9wal=|6>pqO)Rh<&dL03(*%ouBy>l z&lf;UlW6FxmdS1ubmR42>3k!=6 zd%SFHO8&vvtYeFtll3Ggw!gdB5FL5yy{RkCJ)&Y_5Wz%4Lu&{69@^yAi6 z`?lZo1_sIZw`#OEMSxr|Kewe=oSD)0iv9lM*WJ5!Nsf+}R*!9KXQ@JonANIQQK)p0 z8z};AY?En{q4ycFr3oV*@T;kpXv3>E_8)R9X}A2`k4oSEGwqXGcMiaCVKD10BmmPE zdpPTQ0SU+Z2yMI1{fv;WJ_qc6zsdW2=x|W}IBff!;oQ9{Ff;o*vtdHI*bcW|Q{@9L zU0znEC@Sg~$EX!&n6$q(LJzY1>({S?gri|OCjBQ(RV$^p6VFtA7MvV1$YFn?6S~&( zS|+Si$z8ahv#RDMe3t2UnGz=_Yo)OtKA64It#?l0ldzJCr=xapae+D`8UD!alMabH z$~exeRHJ_Q)85%f@z8gR+q@nJMbI+Gfd3OD4w=S5gZKFfv;lpxzXnm9efPK!Iw$AO(!N*cv{q?7SvOR=YuK{4 zElDQ0%c+#_ELo`t3>8FbJW1sCX_QOl%U;KrXx}HQe9R5ARJV- zG?8ktrYhI)FbJ={rd)a9WkfY}ZjvM`;zGFwu=vS8`%7s)B@yn2aX`a5pC9Ma$R?W+ zOVrrSNi=iT=zqKJv^It^6TUp%Q$7dt2%Yyb>H3fXX@YL<>Gur{4RUEh#Vy|6SU5PG zbyI&F?<9w+yq*|Ud58M;{MMc}wCq=HHD*?pmPX@wS}YaIRIG^`Y#=>we4B`4b+#b3 zJBd?y3i}o7J=f^kLfqw@<@nrcO95fxULSBDdrO$=OwQxDv&+J2!)FC`mc<(wwE|$ ztfEs>Q-FLA>|2arTODjomjdRLdn8bxR$Kr?v;c~?o|wS+=tNXMok;*&UTJQ2c3WE{ zGB!3=^UHZPkVS~k8+Ov8^>uX}Hrs|?efcrgQ(y80Jr0P~WTm6|U97!M(x#XqBoYK1{WGlVNqU6nM z<9UjF_Ir8ZWWtcp$Omvpr;zUZT~w@!ll(alG;~UzKS64N3Gc&u!0)<`_LAC0G;hq#&O%M?)Ylh^GzZbW`lMfOrRTOl2yNOY zaa%>lR#gF+0G%XpnR1hyMSh4p(pcPI87oej*jp6e&=x`+ybJZ;a9M@$sRSCM!(k8}^5_cC^Z0VBnHMCxGwWyZ4^m zR1P}upjx03B|rC*_FxD)9eL)q%VBX~X*F4=3R+f96>uBMQ>0w*nNO}Xo6>F#e>|AN z?=nK!_z7tldcAb$|1rlys$g>j5dCwnWc zy4)b9l?&C1jSUQs?vUXP@E5aWaBEe^z}wa%Tl!vRs3G5!sY#jp8d8%F`SV~g3DxD%mVgA_Tj`lMdB zQDKl2v2fbV(!&805NU1Hvlt8^8}w@0ddHuecH-KBYUfiP$pvMqyrtBc2=Mh+pY(OQ zZ`~y%%m!Y((t#?pcXC2mls3|V{#ST}&6@tI1VUqVyoH~TgxZUDnR0a0guQ(Zdv#Q~ z)?;rb;F{}4tqRl5-Ke`H2~qF{`rZYz;>b5VB@D1OQBjKD?>qYwMagwOSjeZp|1~@37ms+nTmRVkM1DP^ zSW#(Rch(eIJm;vQzImN3;?tXFIEiJtv7Jphn<--ocrX@&tK-ktc0;owDtlN(p%$OG zP;#1$xufzmG|0Y;`vDkyOL^5?Ak>_7zzefKd;8{NdDUYL8)70ba{R0B6=?jSrzKN$ zh2Mlr)YtCg>^Tpj1JcfR^__zLy<4w+yXJm}Dd40u>OLN8$j`x9g|>lTK-<92gD9ci z-BuUna2!V8Up@+79m$siRmWV7^FatywHyYT#eA~tNtPBrsz5iv5B8kq#np!o*iY~x zYu|mSfZuR$%H^h0&mx9J!mqZnu|>dmm`FFRS5FP-RT(ZxT4261@1Rd9zBmRvf4*2T z6Rb#Z4OR}j`shlR=IWrpJ29wMUAn(Nn)_H_us;K?^PR;P4g7f5fnAIv8OUxfv~8w` zdo?Y}-1r)!%bfCv_PXw8G-XL;@TxEN`vw2>*xjZDh8tHOXuRS5=Qkec4v=B9GJ(@z zOUq|7!C>TbcmLjs-K9|gFYA{Rlc4{f{$`6U8}NuiL}whqRc*ex`m&gj4?t|otEs8| z^WN2YiGNfQAoGNaOAT-ztlPIe49Aa-T+z_c={Pv{$_}T$xUqLf_$>82hHeQ73F)Nv z7HicI5EJK}9&QO&PXaAIu$O$*vzNF1$Ul5p=#1~2oYaAiP)&VtH)uV z5wvL#_K>>(sAf8Cfa3G*nX}Eo5395q+^hN<3qY#1)QbSjQ4!Gc`NhSY?}4`q&H6t= zA7fZrT2|UGNQu=08JPz-ki_`O@p1e2?^ld%9NJHi2qSrL5D#)>7^&cxSv_>n2uQxw z{>)%#6A>2|7doE}h$tZYaf;(0uhVH&TPCt0u!x|~qhK>{Z~5sD$R+b+98UY_5z?vj zMNvxbt(7*Jw}cS#+0OVX)&l{h^TkyWTJVNW-{L=&TTXGA>IXch7yvZTT7`LH!FSB3 zzSMqiZYBgX1QI$eNRFshGFHQY`%Kz-HjT#;x$<2n&n<(T}2YuE6odPdVl^!Y8Q+IX!46XRCk5MuN$_kA`{|pq>FH;`C=mB$i1>GkORlLPott?cJqb?lDtG$I9VS zJ!bINYz1u|wnb4oU7Wc=IdQd zQQCBI!Y&x^b$S4~4s`tS?ED<3CO9Z)^=H^a2`i94EeNi|ufA4M%#=WG|89Xc*Z>!< za@o@DPUeldef8B>Bn>u>Km0Z>t~zKx_56BGB?rk#mGg!skP-3@i(QJ)7e=--UsZyG z0)vC4qmz@92Nr548a&kF;^OKYSE50UIF}u9jD@6v?gDlm^78V~M>V~@^3l*CNXRyT z`7DTDSuqP!5X=K09E1b}@2yWA936+$^}MnTnuCylCqStim@fm&JAX@S-20*$xe(!( z!~ah)XB`z)_xAlkP`Xu`p#*6V5ESW-kp@8|gqxI33F$7m0Ra(^kZu{eK~V(h0YO?i zW$1kN;r3q7AMaYf^}g#}&w9>(;~e+dXYVUM-_3Om3b@hB7imB1T{syTrGQRIZf-so zpaYJazTb`wUjZ^7DsP|mTIcR`x(W$9EPFVCO2vltRo~M^^K%s9sO`~*hhyzQ*qL6& zgM)*iw>p3%Bt%~rw)p4|1<^~kw6uiIb`KA00m}piQ%ukt3e{}_em6fo04&tvdrB}9 z77}8;Hc}{W*VNn$R8j#{;Oim=9?j0i#s)P}gb~Aa!-(kW6t9AjwR{{yN;S}_woARK zP|-fr-US_hK`lc-iDY;gUtC;J19y7pwwBxU5^Xb>Emu`rtCzrvU{Pv4+l>-G+mVT( zz!;Q3!R8`5f;yyhP^#kj?|XmQTrdo}81DGf`t#4AuURj_M%N?k_U^ zvrkk~B&r7Of!C3~r|!P{qk4dnla!NrN zf3v{haHw|&7~gPTny?OVP`jCyDL!_W5WHIueCB-30 zdgs4#x>sjfTjv)R_P_DAT7e->=A(FjZElu|`<~pj{QmB5`d&S#G8H(dRGP2@3MfVG z3KJ=)s(q@#O<)5mF6{x)t4L^d0$IHDJsrrYNhmTJvRvf}!H9k>AFnh6ca%WFnUP$G*Pt3|RvXFmyRfcSrZy?^e1;86X?UL@mLy6TxZCkU~kcw6sPiX2w83H@a_X zmK!yTkbb#IMn>OMcGc-g$SSPx`k#s^Ha)gH-au;(qoz7wdiQ=+PEAeSg2VfjB=ek> zjouknp}mOyX&yZlEiF!f8aqXx=1{CK(hX>=yslq?@5$)hA5yz!3Sh$Y+XmmCa?F`3 zFhWx!H+7a$?;HAoT+hV$P5?83=ayx1>qDiK z&0C9-{Qr*dItCf?aMWeAcfb7|9qdb&MH#VfzE@dQWzBoat1e)^uX4U=I^PRl?}(KC zbP0ocXa{=4JZ_TF=UXJXXc9oVKRCsl#QZPoEGIg#Uo<4y&6m>)To{t9RfjX)yM#D{ zb+PnSRk^|>SADx&i2b(R#j3&aSbFN#-G*0F3h_yK?1+G0D9dc#}JFC$Xj0WN&Yt#+{l!$0DIH@ATR3Y(MV(PIH`3KlFVPN*g# z3*jbUgpQbNwl8oo~*&S_I+XIm{|LtZ$7an*_X}0OLKBa78;RgFL8RYqIGnAS^s|h_hr|I z+vxgf3haPz=qk8AKf=fK=epA_NkaP175}#hL-?OdQHhU4_Rp2eLW%S5?V4l+SbuIO zWyie{`0xFRSeR1(-me@O!0>+zA5X@~#U-nxq!hK`ZEek-tI6Ke)00s=4PrK9lCp-5 z&L@2TM52EOQC{nY`vn&kvU}~XjWV5XFE3-exVT_pVLj3lb8v7-NlWYO?~kLvV5j?c z3W?h1bo|6{@fY#u<)x)MN7II*qoa7sYPqT-B3QEJj}dM{Wb;hFzy08H72Le$!E3Cj zt@D8I>S28qj&su5+S&{vB9spwKBOhdPWJb}B5jtYX)%bL?e|sZXp9?{$nf8|5F^5a z-bF(Ihq1zb>fwtYRo81BW|sU(npv8d!&h!Sth1yDeGuE(GjNya#y^X6z6uu4DOSv|r4w6crVj zSXtqK6i+}aQt|cN#o4*SteXfh{WTaD7uW3C8lH;_nvH&8YpQV^X-hFQGz5d4oSaZf zyz)ut{_^dcjJEd8jg1XHs{sbZ51O*_@=OvEaG*OvqoVL{5YzXvVSME$k>wt$7oZY( zwFA}@z$qwsz!KNv--*IMA88>k&=e~SvzQ()|dt|a9+jM*&3iA&h z$EhAfN%fDFR=COV2?`2U{3=#2C@P$j(x)PO-uYWgo?2UHbZ3jrP=PrbeI>&Bz`)mkI!}h7j<2!JvWu7U%O>$mJ55dLjGLRp2?e6aK`5ZZ#TUv4^ z0w%vPJw1&;0WKlB&250CqN4KT$&zrMQ}A0Hnc9o+@&Agi#jkc5Rw$mS-1 z*X#i!E33Nz&MJXxSRNb#^h&w+SEO`md3pKS@>0!5z%spWh42>_7k8_`20Y(e8MK(wi9utl#E5^~h($;bkMv8ZM|($9LtzyRaaD@$a{FRKMCTLR{VUh1=Tjqd7_ zRm~Kq^VpuY+w(-E-n$N_q^_rzoSdJVYqC1@q0VXH1`u*sKpcd)Ojlcz12!k6r2N8$ ziD44UV3Wm@eu;})NxI{j=KlpzoK-q}Tf#E0ed;BaW&*r<#oSmVDuM{}cjsZmfH0qI z%O1zi&p#G=7NcPPW?=`6j67rltW9yYdVZfmGC!*8>qlt*@KvP|!1_ISiI3hA8*I-d zN0s8Vc02Kzg)X}uFo!0;=l@_eF?0UQ4)aGNx%*aU?XRo=SI%)H40o0T`kxHt4T zo3DI}+`j@Tb>umZ4eTrs*aY;@9p^Ov7-R0F!&9#dA(k%rS+trZv)4C+#GWnY(_|Nz zKfFb)>);C_Wo3uhu&+M2D2%w$B2_~7%$9NKF9Me~GV$fZ-r$)J*}v_Dt!tb9$v@laQ<;H!!i6uc5AfMtK_cKM?VBw&oIaEVDrtU%yM4e z>6}>AST$eO^GwiCMUBl=z1cqe-qzkxr)3$x`_1j;50nE@ICE-iq`=F2{5xXa7?Qnv zNBPpHT2o>nHIJXhC&n}LKBcJFf{~d1J_VzvhMyf&yjEoC@V&5{Ur9C0D$eJ9mtW6W z%^a_Ib7DFvk%xsWB1POXtK-#U9<7kb$jGCuBPwVPOzw0yVY1i>kLOJq=2P}g!%EdP zG)Rq0rkQwYUMw@f!n25Sx-Orw-?rQ}XL9tdgE3s3?{8VetfGAgcN@E+lCBc3h-byt zrLvowo73-kxez-FUZb0=tgP4k2gb(q#@}RS^1^Un^QE=ZWVQBFn&Vq@bBwTX5CJ$7 zZz=jZDM3hw&(S7}n+8`k7|zK2yk_^NuudV()Cf3Y$VdN-R7U3T2b&2LAw((QR&qPm-k!YxIEwVz{Y@`y(tZCXpnz) zc|r(N7Z!@WVufK4H8EfyX;xHMYmZx4TSss|t$Fk@X1nF|aYknTG!RS}uw-6i-Mi(+ z^XDsrIeu#|wyYr$cP%dS z@4uNc@4GL2CZv^kMGKNE;xX0wSUJ4GeKT@sNE2*`;Do)YX~4>gRY9Rx4-8lzACTd! za86C5UQ$`^x4$aQUF2EQ)t^3%`n&PdU0y%`i3tN&!S$1o`>y+YG|eJEn>4~Z&TLoA z@`kN0C*D#Y_oL5~=h{4G7&d=tV3qtVAaS%&Hk}r-TCWai3CNOusW8j~^B1jk;7F8c zF>dZo*gy`V>;>r!4BTp`Q6t)DX-0_dG?)7`vDK4J>e)9Zklq$Fo8XPKQCTum*u~)e z@D>FudfUFIivq3*Xli-{ETCh0x<%vMq4ivMx;8YFhz^g2CQZWiJIG*1o3%4AnD6O< zoikiatXUqagA;LGQP0`U5c7UM-xaZoMjsxAg@s{1&J>Tij(@wYr>96Gy|-5t<_{?4 z`Sa)0cI5>Hul;yAI07pxE1SS}5s{ITr@gvFpPs%6J$_3q{)R9}a`#ZN75g{6Uy0&N zKp1|Ui^M%Jm_ez*x63-+X31DuKm+4(l$hmm#`h;sgCnXJE;hTQ+KI_B`K3HWcUVn+ zn%Cyn6c=$w9S1eQbUJ6XeBn=P2bY2rAvEMg_;$>lwDo<{ylgkOvn!Q8-kIwpg~Q`O z(q>|3#|1pQ^5Y{LNZ-M6;wOqN#vnJx!X>5)ra%OhpvB?f;dyg;c9gEF2K_J#RQAKM zJyxFih-B}FWoA}h-i?5OfbhsjK%X~Xym+zmiNe_A%WFowWega|`HBdHZ_g=_kQEqo zuQ4|l%idni&v@{skIH^GY;9ML6oUXu17DA!Pp8gy=}e6ZxKOnF$qlR0QbOP@?=IQV z^^=2XH-yDCVdc+ zIk?^@zPsDIrv>vDKHXakQvS0J*A}X(sxBw^)6>)ER#w7OQYc?cH&HErPY+5;AE2EiYXt91yG^abj1e-2DOhYC8Q zGF&^xL}Eb)M`}I9339oRI!r3zpzeU3Yk)w-#ekBhdta*AP zs0H%|TIvq)s_f)E@$kVB?QFe5kg`(*EQu`oGhzs7?whm+UdJIM3@I-1`3VT9fb#7V(VByYpMtKp(~cA{#m}gr1jQ9Ha11^Nw4s{ z-9LA99=fbhjWkzq8MNG}@;f`Wx4Q4%BsoRVfB<0 z_s^jP>2c!Co+U;uLWWhEi`OS1b(q~6C+@qpB`pDXIAPMv%*=T8w~n?ppWlTKB@K-X zPJr!LnV81*gOXm3iD4BcF3-(;#utU z$8f{1&CSh)#8aQmHz0rBzI}U_m-liw!EShlW*aB_wq4V@tEyvq0B169N813-(v&yH zi?PvRg|4!oI_G1iSDZZ3-pppMNKe;B>)8{>k;sWWT*1A<~dyfO?oo z0jqzs?0>%SIc8_CZxmMV*yrk zT}N%!PizciVdCNAJI#0D?g8ocW8cuwu)=-Q01F$t^Xpe7@x_gy4=R+x_O!X0t1g){ z`|D$*VPO2S5y(u3VRqtF}!Vs+A6ID-+K8cxD%NQ%p z%e&}0ll4MixmOz??VT_47e$z^Oi9Al*0!#`o{@tC&&bFqJT^8IOjJ`-({UZe?dk1p zHr3$9yZA&%NC*cHPg+qC2gH^Ez%Yi*Ubnmtw;*E8Q_Gy*DAe1RkERUR*>OBNI+_J( z|4V;=SaY*j%gI`CJ_?OSca}YCR99DradL8wPfq4EHPL?k`qgT*=$82LFY@4!5HUSt zK(({m+i|nACehSFcmVp_kI~Ccvuzm1{P1&$@=y>rqbd2X;o{;dDk-(UW|VnfUQV2< z8oIaV3S^-fsze`;Gp*DBiO0^)UgvXskBgg|AGk=$+qc;zB?N%g6;)JZK-7&-OZyg; zW<>e#iHVpD6*R>DV)+6V;U+}s=v5t01!=h;5Eu9%pZKw$vWnyo*jzj+g@P&<-YA=acnLrh&u ztMg~Q%i`qv>C_Gp-FthlC(h3ImU>fzI>U&~W?Fm!76$|cVWP^7UC$< zCTn>?5Q`2E#{q_eFq%f%>T&5;VL`tXH$L>K7FJf_*28)2 zlao)gVgmv&Al2l$stE}SFo#_`yNT)mkSw5I*-_8Gpshxx83ojd>mMwb$@ZwoITAiN z!LQU$jEQj(6?19zS=Bj9{LL&c@<0ZGNXI-hUaBu7VGHtdzB=tPc#Ta=|GuJvWNmG2 zWdga*DW(g+J~ApQ>%)f-AaBp+4!{S-gs&!6R!2WEVnjW*-h*81<>l4)nD(4&tlT&Z z#NM*9vJSyIHg;a#ZeZ^~uHw?s(Y++fv5Z&#P*7453_Pf}xA&&5EVGve0oI_gvJ0lv z-tzN5=WPXlJr{}ppE`N_PX~J=B3OHRLp4Z_N5Z$984TJM{(Qq77fB-RNcr!7y0{P# jivHi2-~Z$A^OqRbc_JhqlU?(n!&W7^$FgP8CV~G2Vvk?X literal 0 Hc-jL100001 diff --git a/doc/userguide/rules/datasets.rst b/doc/userguide/rules/datasets.rst index 5e08350b20..591efe1769 100644 --- a/doc/userguide/rules/datasets.rst +++ b/doc/userguide/rules/datasets.rst @@ -96,6 +96,31 @@ hashsize .. note:: 'load' and 'state' or 'save' and 'state' cannot be mixed. +Example rules could look like: + +1. Detect unique User-Agents: + +.. container:: example-rule + + alert http any any -> any any (msg:"LOCAL HTTP new UA"; http.user_agent; dataset:set,http-ua-seen, type string, state http-ua-seen.csv; sid:8000001; rev:1;) + +2. Detect unique TLDs: + +.. container:: example-rule + + alert dns $HOME_NET any -> any any (msg:"LOCAL DNS unique TLD"; dns.query; pcrexform:"\\.([^\\.]+)$"; dataset:set,dns-tld-seen, type string, state dns-tld-seen.csv; sid:8000002; rev:1;) + +Following image is a pictorial representation of how the ``pcrexform`` works +on domain names to find TLDs in the dataset ``dns-tld-seen``: + +.. image:: dataset-examples/detect-unique-tlds.png + +Notice how it is not possible to do certain operations alone with datasets +(example 2 above), but, it is possible to use a combination of other rule +keywords. Keep in mind the cost of additional keywords though e.g. in the +second example rule above, negative performance impact can be expected due +to ``pcrexform``. + datarep ~~~~~~~ -- 2.47.2