mirror of https://github.com/OISF/suricata
lua detect: expose stream payload
Allow a script to set the 'stream' buffer type. This will add the script to the PMATCH list. Example script: alert tcp any any -> any any (content:"html"; lua:stream.lua; sid:1;) function init (args) local needs = {} needs["stream"] = tostring(true) return needs end -- return match via table function match(args) local result = {} b = tostring(args["stream"]) o = tostring(args["offset"]) bo = string.sub(b, o); print (bo) return result end return 0pull/1138/merge
parent
5b9c6d4774
commit
944276b988
Loading…
Reference in New Issue