I am new here and also new to Suricata and I need help. I have rule which fires when it sees:
content:“text1” followed by content:“text2” with distance:0
I need to modify the rule in modify.conf in such a way, that if above is true and there is third content:“text3”, then do not fire alert.
Can it be done? How? Thanks in advance for suggestions.