Skip to content

Commit

Permalink
tls: add check for catch-all rule logging app-layer metadata
Browse files Browse the repository at this point in the history
Ticket: 7530
  • Loading branch information
catenacyber committed Dec 2, 2024
1 parent 09c0a3b commit cde493b
Show file tree
Hide file tree
Showing 2 changed files with 12 additions and 0 deletions.
4 changes: 4 additions & 0 deletions tests/firewall/firewall-06-tls-sni-enforce/suricata.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,10 @@ stats:
# Add stream events as stats.
#stream-events: false

detect:
stream-tx-log-limit: 4
guess-applayer-tx: true

# Configure the type of alert (and other) logging you would like.
outputs:
- eve-log:
Expand Down
8 changes: 8 additions & 0 deletions tests/firewall/firewall-06-tls-sni-enforce/test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,14 @@ checks:
count: 26
match:
event_type: alert
- filter:
min-version: 8
# check for https://redmine.openinfosecfoundation.org/issues/7350
count: 4
match:
event_type: alert
alert.signature_id: 3
tls.sni: raw.githubusercontent.com
- filter:
count: 1
match:
Expand Down

0 comments on commit cde493b

Please sign in to comment.