doc: update http.stat_code keyword information

Ticket: 3025

Signed-off-by: jason taylor <jtfas90@gmail.com>
pull/10795/head
jason taylor 2 years ago committed by Victor Julien
parent 71d8488cb5
commit 271321249f

@ -829,15 +829,25 @@ Example HTTP Request::
http.stat_code http.stat_code
-------------- --------------
With the ``http.stat_code`` sticky buffer, it is possible to match The ``http.stat_code`` keyword is used to match on the HTTP status code
specifically and only on the HTTP status code buffer. The keyword can that can be present in an HTTP response.
be used in combination with all previously mentioned content modifiers
like ``distance``, ``offset``, ``nocase``, ``within``, etc. It is possible to use any of the :doc:`payload-keywords` with the
``http.stat_code`` keyword.
Example HTTP Response::
Example of ``http.stat_code`` in a HTTP response: HTTP/1.1 200 OK
Content-Type: text/html
Server: nginx/0.8.54
.. container:: example-rule
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"HTTP Stat Code Response \
Example"; flow:established,to_client; :example-rule-options:`http.stat_code; \
content:"200";` classtype:bad-unknown; sid:117; rev:1;)
Example of the purpose of ``http.stat_code``: .. note:: ``http.stat_code`` does not include the leading or trailing space
.. _http.stat_msg: .. _http.stat_msg:

Loading…
Cancel
Save