checks:
- filter:
+ requires:
+ lt-version: 9
count: 1
match:
event_type: alert
verdict.reject-target: to_server
verdict.reject: ["tcp-reset"]
- filter:
+ requires:
+ min-version: 9
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ pcap_cnt: 1
+ verdict.action: drop
+ verdict.reject_target: to_server
+ verdict.reject: ["tcp-reset"]
+ - filter:
+ requires:
+ lt-version: 9
count: 1
match:
event_type: alert
verdict.reject-target: to_server
verdict.reject: ["tcp-reset"]
- filter:
+ requires:
+ min-version: 9
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+ pcap_cnt: 1
+ verdict.action: drop
+ verdict.reject_target: to_server
+ verdict.reject: ["tcp-reset"]
+ - filter:
+ requires:
+ lt-version: 9
count: 1
match:
event_type: drop
verdict.action: drop
verdict.reject-target: to_server
verdict.reject: ["tcp-reset"]
+ - filter:
+ requires:
+ min-version: 9
+ count: 1
+ match:
+ event_type: drop
+ pcap_cnt: 1
+ verdict.action: drop
+ verdict.reject_target: to_server
+ verdict.reject: ["tcp-reset"]
- filter:
count: 0
match:
drop.reason: rules
verdict.action: drop
- filter:
+ requires:
+ lt-version: 9
count: 1
match:
event_type: alert
verdict.reject-target: to_client
verdict.reject: [icmp-prohib]
- filter:
+ requires:
+ min-version: 9
+ count: 1
+ match:
+ event_type: alert
+ verdict.action: drop
+ verdict.reject_target: to_client
+ verdict.reject: [icmp-prohib]
+ - filter:
+ requires:
+ lt-version: 9
count: 1
match:
event_type: drop
verdict.action: drop
verdict.reject-target: to_client
verdict.reject: [icmp-prohib]
+ - filter:
+ requires:
+ min-version: 9
+ count: 1
+ match:
+ event_type: drop
+ drop.reason: rules
+ verdict.action: drop
+ verdict.reject_target: to_client
+ verdict.reject: [icmp-prohib]
alert.signature_id: 1
verdict.action: alert
- filter:
+ requires:
+ lt-version: 9
count: 1
match:
event_type: alert
verdict.action: alert
verdict.reject-target: both
verdict.reject: [icmp-prohib]
+ - filter:
+ requires:
+ min-version: 9
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2
+ verdict.action: alert
+ verdict.reject_target: both
+ verdict.reject: [icmp-prohib]
# match on rule `pass` for hostname www.wireshark.org
- filter:
count: 1
checks:
- filter:
+ requires:
+ lt-version: 9
count: 2
match:
event_type: alert
verdict.action: alert
verdict.reject-target: to_client
verdict.reject: [icmp-prohib]
+ - filter:
+ requires:
+ min-version: 9
+ count: 2
+ match:
+ event_type: alert
+ verdict.action: alert
+ verdict.reject_target: to_client
+ verdict.reject: [icmp-prohib]
match:
verdict.action: drop
- filter:
+ requires:
+ min-version: 9
+ count: 4
+ match:
+ verdict.action: drop
+ verdict.reject_target: to_client
+ verdict.reject[0]: tcp-reset
+- filter:
+ requires:
+ lt-version: 9
count: 4
match:
verdict.action: drop