Project

General

Profile

Actions

Feature #6857

open

iprep: support seeing if rule is part of a rep list

Added by Victor Julien 2 months ago. Updated 8 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

E.g. something like iprep:src,myCategory,isset; and iprep:src,myCategory,isnotset;. Not sure about the keyword, just used that is done in dataset.


Related issues 1 (1 open0 closed)

Related to Suricata - Bug #6834: iprep: rule with '=,0' can't matchResolvedVictor JulienActions
Actions #1

Updated by Victor Julien 2 months ago

  • Related to Bug #6834: iprep: rule with '=,0' can't match added
Actions #2

Updated by Jason Ish 19 days ago

isset and isnotset do map well to the dataset idea, but couldn't -1 be an option that also fits well with the current syntax?

Actions #3

Updated by Victor Julien 8 days ago

Jason Ish wrote in #note-2:

isset and isnotset do map well to the dataset idea, but couldn't -1 be an option that also fits well with the current syntax?

I think making things explicit is preferred over using a magic value.

Actions #4

Updated by Victor Julien 8 days ago

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Victor Julien
  • Target version changed from TBD to 8.0.0-beta1
Actions

Also available in: Atom PDF