Hi everyone, does Suricata support OR/AND Operator Logical, i want write a rule have http.uri.raw contains keyword “A” or “B”. I see prce regula can do that but Is there are any other way? like content: A|B, content: A OR content: B
Hi,
Unfortunately at the moment there is no way to do this with content matches without using pcre in a single rule.
JT
1 Like
Thanks you very much