mirror of https://github.com/OISF/suricata
doc: add file.name information to smtp keyword doc
Signed-off-by: jason taylor <jtfas90@gmail.com>pull/9985/head
parent
9d1ad0187e
commit
fc81c99b58
@ -0,0 +1,19 @@
|
||||
SMTP Keywords
|
||||
=============
|
||||
|
||||
.. role:: example-rule-options
|
||||
|
||||
file.name
|
||||
---------
|
||||
|
||||
The ``file.name`` keyword can be used at the SMTP application level.
|
||||
|
||||
Signature Example:
|
||||
|
||||
.. container:: example-rule
|
||||
|
||||
alert smtp any any -> any any (msg:"SMTP file.name usage"; \
|
||||
:example-rule-options:`file.name; content:"winmail.dat";` \
|
||||
classtype:bad-unknown; sid:1; rev:1;)
|
||||
|
||||
For additional information on the ``file.name`` keyword, see :doc:`file-keywords`.
|
Loading…
Reference in New Issue