--- /dev/null
+%YAML 1.1
+---
+
+stats:
+ enabled: yes
+ interval: 8
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filetype: regular
+ filename: eve.json
+ types:
+ - stats
+ - alert
+ - flow
+ - http
+ - drop:
+ alerts: yes
+ flows: all
+
+firewall:
+ policies:
+ packet-filter: ["accept:hook", "alert"]
+ http:
+ request-started: ["accept:hook"]
+ request-line: ["accept:hook"]
+ request-headers: ["accept:hook"]
+ request-body: ["accept:hook"]
+ request-trailer: ["accept:hook"]
+ request-complete: ["accept:hook"]
+ response-started: ["accept:hook"]
+ response-line: ["accept:hook"]
+ response-headers: ["accept:hook"]
+ response-body: ["accept:hook"]
+ response-trailer: ["accept:hook"]
+ response-complete: ["accept:hook"]
--- /dev/null
+requires:
+ min-version: 9
+
+pcap: ../../flowbit-oring/input.pcap
+
+args:
+ - --simulate-ips
+ - -k none
+
+checks:
+# We should see an alert for SID 101.
+- filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 101
+# Should see a default packet policy alert for each packet.
+- filter:
+ count: 10
+ match:
+ event_type: alert
+ alert.signature_id: 2201000