Project

General

Profile

Actions

Bug #7630

open

pass rules with alert; keyword log with a verdict of "alert" instead of "pass"

Added by Jesse Lepich 4 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

This rule:

pass tls $HOME_NET any -> any any (alert; tls.sni; content:"checkip.amazonaws.com"; sid:202502272;)

produces an alert log entry with a verdict of "alert" instead of "pass":

"verdict": {"action": "alert"},

No data to display

Actions

Also available in: Atom PDF