--- /dev/null
+alert http any any -> any any (http.uri; content:"/test_lastline_blocking"; sid:1;)
--- /dev/null
+requires:
+ min-version: 7
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: http
+ http.url: /test_lastline_blocking
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
--- /dev/null
+alert http any any -> any any (http.uri; content:"/test_lastline_blocking"; sid:1;)
--- /dev/null
+requires:
+ min-version: 7
+
+checks:
+- filter:
+ count: 1
+ match:
+ event_type: http
+ http.url: /test_lastline_blocking
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1