Project

General

Profile

Actions

Documentation #3274

open

doc: some inconsistency between http docs keywords description

Added by Peter Manev about 5 years ago. Updated 8 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

It seems the command line help sometimes differs form the online docs in terms of what is sticky buffer.
Example http.uri and http.uri.raw

https://suricata.readthedocs.io/en/latest/rules/http-keywords.html#http-keywords

and

 /opt/suritest/bin/suricata --list-keywords=http.uri
= http.uri =
Description: sticky buffer to match specifically and only on the normalized HTTP URI buffer
Features: No option,sticky buffer
Documentation: https://suricata.readthedocs.io/en/latest/rules/http-keywords.html#http-uri-and-http-raw-uri

/opt/suritest/bin/suricata --list-keywords=http.uri.raw
= http.uri.raw =
Description: sticky buffer to match specifically and only on the raw HTTP URI buffer
Features: No option,sticky buffer
Documentation: https://suricata.readthedocs.io/en/latest/rules/http-keywords.html#http-uri-and-http-raw-uri

/opt/suritest/bin/suricata -V
This is Suricata version 5.0.0-dev (64a789bbf 2019-10-18)

Actions

Also available in: Atom PDF