Is it possible to create an alert based on multiple files?

Is it possible to create an alert based on multiple files?
When I receive multiple files from a certain source with certain keywords in a given time, I do not want to receive an alert. But when I receive multiple files from a certain source with certain keywords in a given time and I recognize special keywords in another file 5 minutes later, then I should receive an alert.

Is it possible to write such a rule?

Best regards Erlind

Hi @Erlind ! Welcome to our forum. :slight_smile:

I believe so.
I think you should be looking at a combination of:

  1. 8.13. HTTP Keywords — Suricata 8.0.0-dev documentation
  2. 8.37. Thresholding Keywords — Suricata 8.0.0-dev documentation
  3. noalert;

Could you please look at these and try to make a rule matching your usecase? Let us know if you face any troubles.