diff --git a/tests/detect-vlan-id/README.md b/tests/detect-vlan-id/README.md new file mode 100644 index 000000000..4e7d36f93 --- /dev/null +++ b/tests/detect-vlan-id/README.md @@ -0,0 +1,4 @@ +PCAP +==== + +Pcap created with scapy diff --git a/tests/detect-vlan-id/input.pcap b/tests/detect-vlan-id/input.pcap new file mode 100644 index 000000000..e146ce45f Binary files /dev/null and b/tests/detect-vlan-id/input.pcap differ diff --git a/tests/detect-vlan-id/test.rules b/tests/detect-vlan-id/test.rules new file mode 100644 index 000000000..2c02e2c69 --- /dev/null +++ b/tests/detect-vlan-id/test.rules @@ -0,0 +1 @@ +alert ip any any -> any any (msg:"Vlan ID is equal to 300"; vlan.id:300; sid:1;) diff --git a/tests/detect-vlan-id/test.yaml b/tests/detect-vlan-id/test.yaml new file mode 100644 index 000000000..6b607cd82 --- /dev/null +++ b/tests/detect-vlan-id/test.yaml @@ -0,0 +1,12 @@ +requires: + min-version: 7 + +args: +- -k none + +checks: +- filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1