You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide
Yash Datre 43bc2db41e detect: extend app-layer-protocol to accept a pipe-separated value list
Extend the app-layer-protocol keyword to accept a pipe-separated list of
protocol values, so a single rule can match any of several protocols:

    app-layer-protocol:[!]<proto1>|<proto2>[|...][,<qualifier>]...;

A non-negated list matches when the flow's protocol equals any listed value
(OR); a negated list matches when it equals none of them (NOR). The
single-value form and the trailing mode qualifier are unchanged.

Matching keeps the historical AppProtoEquals() equivalences by default
(dns/doh2, http/http1/http2, dcerpc/smb, ...). An `exact` qualifier selects
strict identity matching with no equivalences and no http umbrella; it
combines with a direction mode in any order. Because a flow is never the
generic ALPROTO_HTTP, `http,exact` is rejected at load.

Values are expanded once at rule load into an effective match-set bitmask, so
the per-packet match is a single bitmask test. Single-value rules remain
prefilterable; multi-value rules are excluded from prefiltering and an
explicit prefilter on them is rejected. Conflicting keyword combinations
(duplicate or overlapping negations, mixed positive/negated) are rejected at
load. Engine-analysis reports the effective match set.

Ticket: 7705
1 month ago
..
3rd-party-integration
_static
appendix
capture-hardware pcap-file: skip setvbuf on non-seekable streams 2 months ago
configuration ftp: do not create more than max-tx transactions 1 month ago
devguide detect: convert tx_progress to uint8_t 1 month ago
file-extraction
firewall doc/firewall: update hooks & configuration examples 2 months ago
install doc/userguide: update windivert instructions 8 months ago
ips src: doc: remove double-space typos 7 months ago
licenses
lua http-log: remove support for http-log 2 months ago
manpages doc: improve manpage of suricatasc 3 months ago
output doc: dhcp eve note for option 52 overload 2 months ago
partials pcap-file: skip setvbuf on non-seekable streams 2 months ago
performance http-log: remove support for http-log 2 months ago
plugins
protocols
reputation
rule-management userguide: add references to rules/README to docs 5 months ago
rules detect: extend app-layer-protocol to accept a pipe-separated value list 1 month ago
upgrade
.gitignore
Makefile.am userguide/Makefile: don't add "install" to EXTRA_DIST 6 months ago
Makefile.sphinx
README.md
acknowledgements.rst
command-line-options.rst
conf.py doc: address config conversion note 3 months ago
convert.py
docutils.conf
generate-evedoc.sh
index.rst
initscripts.rst
install.rst docs: use correct suricata version mentions 7 months ago
make-sense-alerts.rst
public-data-sets.rst doc: add more public datasets 5 months ago
quickstart.rst doc: clarify suricata.yaml location per install 2 months ago
requirements.txt
security.rst
support-status.rst
unix-socket.rst
upgrade.rst flowbits: deprecate toggle command 2 months ago
verifying-source-files.rst docs: use correct suricata version mentions 7 months ago
what-is-suricata.rst

README.md

Suricata User Guide

This directory contains the Suricata Guide. The Suricata Developer's guide is included as a chapter of the Guide. The Sphinx Document Generator is used to build the documentation. For a primer os reStructuredText see the reStructuredText Primer.

Verifying Changes

There are a number of output formats to choose from when making the source documentation locally (e.g. html, pdf, man).

The documentation source can be built with make -f Makefile.sphinx html. Substitute the 'html' word for desired output format.

There are different application dependencies based on the output desired.