Skip to content

Detect int count 7211 v1 - #13897

Closed
catenacyber wants to merge 2 commits into
OISF:mainfrom
catenacyber:detect-int-count-7211-v1
Closed

Detect int count 7211 v1#13897
catenacyber wants to merge 2 commits into
OISF:mainfrom
catenacyber:detect-int-count-7211-v1

Conversation

@catenacyber

Copy link
Copy Markdown
Contributor

Link to ticket: https://redmine.openinfosecfoundation.org/issues/
https://redmine.openinfosecfoundation.org/issues/7211

Describe changes:

  • fix some typo in json schema
  • Allows to match on the number of integers in case of a multi-integer

SV_BRANCH=OISF/suricata-verify#2662

enip.command is not a keyword nor an alias
Ticket: 7211

Allows to count the number of elements, without matching on
individual elements
@suricata-qa

Copy link
Copy Markdown

Information: QA ran without warnings.

Pipeline = 27696

without matching to a specific value.

The syntax is::
keyword: count [mode] value;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should this be extended (separately) to multi-buffer? dns.query: count >1;

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes ! that is done in #13902 which builds on top of that PR ;-)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ping @victorjulien ;-)

@victorjulien victorjulien added this to the 9.0 milestone Oct 16, 2025
@victorjulien

Copy link
Copy Markdown
Member

Merged in #14055, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants