-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
test: add test for vlan.id - v3 #2134
base: master
Are you sure you want to change the base?
Conversation
@@ -0,0 +1,3 @@ | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 200 with especific layer"; vlan.id:200,1; sid:1;) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit typo especific
@@ -0,0 +1,3 @@ | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 200 with especific layer"; vlan.id:200,1; sid:1;) | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 300 with explicit 'any' layer "; vlan.id:300,any; sid:2;) | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 400"; vlan.id:300; sid:3;) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
msg:"Vlan ID is equal to 400"; vlan.id:300;
These do not seem to match...
count: 1 | ||
match: | ||
event_type: alert | ||
alert.signature_id: 1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could we check the vlan id in the alert data ?
Ticket: #1065
Description:
Redmine ticket: https://redmine.openinfosecfoundation.org/issues/1065
Suricata PR: OISF/suricata#12103
Previous PR: #2124