Dataset rules not triggering at all

Hi teams,

I try to use dataset with rules.

I created a specific rule using dataset.

I have double check that each line contains only the datasets base64 string and nothing else - no spaces at the end of the line,tabs,carriage returns etc …

But no alert raised with this rule…
It works with basic rules not using dataset…

Any idea?



Hi @AntoninHL ! Welcome to our forum! :slight_smile:
Could you please share the rules and if possible a pcap which you’d expect them to alert on?
Also, the Suricata version that you’re running.

There are working examples in our regression test suite, e.g.