I have a sample where there are two Accept header entries. I was going to use http.header_names to specify order, so in this case it would be something like content:“Accept|0d 0a|Accept|0d 0a|Accept-Language|0d 0a|”. The rule doesn’t fire against said pcap with the double Accept defined. It will fire with content:“Accept|0d 0a|Accept-Language|0d 0a|”;
Is the apparent deduplication expected? It seems unintended based on the docs. Thanks in advance!
JT