As it is always present since 7
# as the test level requires above.
requires:
features:
- - HTTP2_DECOMPRESSION
+ - HAVE_JA4
# The number of records this filter should match.
count: 1
event_type: anomaly
# check gzip decompresser
- filter:
- requires:
- features: [HTTP2_DECOMPRESSION]
count: 1
match:
event_type: fileinfo
fileinfo.size: 639
# check brotli decompresser
- filter:
- requires:
- features: [HTTP2_DECOMPRESSION]
count: 1
match:
event_type: fileinfo
-requires:
- features:
- - HTTP2_DECOMPRESSION
-
# disables checksum verification
args:
- -k none --set app-layer.protocols.http2.enabled=true