Actions
Bug #180
closed
RR
PR
no alert with ip proto GRE on suricata today git and v0.9.1
Bug #180:
no alert with ip proto GRE on suricata today git and v0.9.1
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
On suricata today git (ca7f54de2596f24663f18d079681d8cfa25fe81f) and v0.9.1, I don't have
alert with joigned pcap file.
I have added this simple example sig:
alert ip any any -> any any (msg:"GRE suricata test"; ip_proto:47; classtype:attempted-admin; sid:9431292; rev:1; )
and alert fire of course with snort.
No other sig on my test, no error on suricata.log.
Regards
Rmkml
Files
Actions