]> git.ipfire.org Git - people/stevee/suricata-verify.git/commitdiff
dns-udp-double-request-response: add dns eve v2 test
authorJason Ish <jason.ish@oisf.net>
Mon, 15 Mar 2021 21:38:57 +0000 (15:38 -0600)
committerJason Ish <jason.ish@oisf.net>
Tue, 16 Mar 2021 04:25:35 +0000 (22:25 -0600)
tests/dns-udp-double-request-response-v1/README.txt [new file with mode: 0644]
tests/dns-udp-double-request-response-v1/dns-udp-double-request-response.pcap [new file with mode: 0644]
tests/dns-udp-double-request-response-v1/suricata.yaml [new file with mode: 0644]
tests/dns-udp-double-request-response-v1/test.yaml [new file with mode: 0644]
tests/dns-udp-double-request-response/suricata.yaml
tests/dns-udp-double-request-response/test.yaml

diff --git a/tests/dns-udp-double-request-response-v1/README.txt b/tests/dns-udp-double-request-response-v1/README.txt
new file mode 100644 (file)
index 0000000..d0a46a6
--- /dev/null
@@ -0,0 +1,8 @@
+Test 2 UDP DNS requests followed back to back with no response, then
+the 2 responses being received.
+
+Prior to Suricata 3.2 the first request would be marked as having a
+reply lost when the second request was seen.
+
+Related issue:
+https://redmine.openinfosecfoundation.org/issues/1923
diff --git a/tests/dns-udp-double-request-response-v1/dns-udp-double-request-response.pcap b/tests/dns-udp-double-request-response-v1/dns-udp-double-request-response.pcap
new file mode 100644 (file)
index 0000000..43b47e6
Binary files /dev/null and b/tests/dns-udp-double-request-response-v1/dns-udp-double-request-response.pcap differ
diff --git a/tests/dns-udp-double-request-response-v1/suricata.yaml b/tests/dns-udp-double-request-response-v1/suricata.yaml
new file mode 100644 (file)
index 0000000..5f7eded
--- /dev/null
@@ -0,0 +1,10 @@
+%YAML 1.1
+---
+
+outputs:
+  - eve-log:
+      enabled: yes
+      filename: eve.json
+      types:
+        - dns:
+            version: 1
diff --git a/tests/dns-udp-double-request-response-v1/test.yaml b/tests/dns-udp-double-request-response-v1/test.yaml
new file mode 100644 (file)
index 0000000..f9d87cb
--- /dev/null
@@ -0,0 +1,16 @@
+requires:
+  features:
+    - HAVE_LIBJANSSON
+  lt-version: 7
+
+checks:
+  - filter:
+      count: 2
+      match:
+        event_type: dns
+        dns.type: query
+  - filter:
+      count: 9
+      match:
+        event_type: dns
+        dns.type: answer
index 5f7eded22dbe6f08572e51f398c349ce1949c786..bf949095f0e45a5834c5e1a5805e1be565718918 100644 (file)
@@ -7,4 +7,3 @@ outputs:
       filename: eve.json
       types:
         - dns:
-            version: 1
index 7804b105beeb67cb6a822b6745e7e439395f8abd..bd8327966e4cf30fd7b6d8ef3e8baf6227ec03d3 100644 (file)
@@ -9,7 +9,7 @@ checks:
         event_type: dns
         dns.type: query
   - filter:
-      count: 9
+      count: 2
       match:
         event_type: dns
         dns.type: answer