Actions
Task #5050
openFeature #4174: tracking: app-layer frame inspection support
rules/frames: settle on rule syntax
Effort:
Difficulty:
Label:
Description
Currently frames are accessed through a frames
keyword. We could also allow using the frame names directly in rules, like alert sip ... (request_line; content:"REGISTER"; ...)
. This needs more thought about how it ties in to other rule syntax.
See also https://github.com/OISF/suricata/pull/6915/commits/ae71c5813fd77d22a5e03b71b1012d670b13b698
Actions