Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions tests/eve-suricata-version/suricata.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@

outputs:
- eve-log:
version: 2
enabled: yes
suricata-version: yes
types:
Expand Down
6 changes: 5 additions & 1 deletion tests/eve-suricata-version/test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -64,4 +64,8 @@ checks:
event_type: fileinfo
dest_ip: 192.168.118.10
has-key: suricata_version

- filter:
min-version: 9
count: 53
match:
has-key: v
1 change: 1 addition & 0 deletions tests/force-eve-logging-v1/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Test that forcing EVE version to 1 trigger app_proto not to be logged.
1 change: 1 addition & 0 deletions tests/force-eve-logging-v1/input.pcap
23 changes: 23 additions & 0 deletions tests/force-eve-logging-v1/suricata.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
%YAML 1.1
---

outputs:
- eve-log:
enabled: yes
filetype: regular #regular|syslog|unix_dgram|unix_stream|redis
filename: eve.json
version: 1
types:
- alert:
payload: yes
payload-buffer-size: 4kb
payload-printable: yes
packet: yes
xff:
enabled: yes
mode: extra-data
deployment: reverse
header: X-Forwarded-For
- flow
- smtp
- tls
26 changes: 26 additions & 0 deletions tests/force-eve-logging-v1/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
args:
- -k none

requires:
min-version: 9

checks:
- filter:
count: 1
match:
event_type: smtp
- filter:
count: 0
match:
smtp.helo: "desktop.unx.ca"
not-has-key: "email"
app_proto: smtp
- filter:
count: 1
match:
event_type: tls
- filter:
count: 0
match:
event_type: tls
app_proto_orig: smtp
6 changes: 6 additions & 0 deletions tests/smtp-startssl/test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,9 @@ checks:
match:
smtp.helo: "desktop.unx.ca"
not-has-key: "email"
- filter:
min-version: 9
count: 1
match:
event_type: tls
app_proto_orig: smtp
Loading