-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
test: add test for vlan.id - v3 #2134
Conversation
@@ -0,0 +1,3 @@ | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 200 with especific layer"; vlan.id:200,1; sid:1;) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit typo especific
@@ -0,0 +1,3 @@ | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 200 with especific layer"; vlan.id:200,1; sid:1;) | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 300 with explicit 'any' layer "; vlan.id:300,any; sid:2;) | |||
alert ip any any -> any any (msg:"Vlan ID is equal to 400"; vlan.id:300; sid:3;) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
msg:"Vlan ID is equal to 400"; vlan.id:300;
These do not seem to match...
count: 1 | ||
match: | ||
event_type: alert | ||
alert.signature_id: 1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could we check the vlan id in the alert data ?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry, I didn't understand the question. Could you be more specific, please?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we we add in this match section a check about vlan.id: 200
? (with the good syntax and value)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think so. Should I use these other commits as examples for the implementation?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
schema.json tells me that it should be vlan[0]: 200
Ticket: #1065
Description:
Redmine ticket: https://redmine.openinfosecfoundation.org/issues/1065
Suricata PR: OISF/suricata#12103
Previous PR: #2124