[Oisf-users] Suricata 1.4 simple alert rule, first visit to website not triggering an alert

Eoin Miller eoin.miller at trojanedbinaries.com
Thu Jan 10 20:34:24 UTC 2013

On 1/10/2013 19:57, Vincent Fang wrote:
> alert http any any -> <> any (msg:
> "visiting businessweek")

Maybe try alert tcp instead of alert http.

-- Eoin

More information about the Oisf-users mailing list