here is my rule.
alert udp any any → any ![443,80] (msg:“quic init request”; content:“|c2 00 00 00 01 14|”; depth:6; sid:3; rev:1;)
but i want see the sni info in the eve log.
i am try to write a “text parser” for quic protocol.
To get sni, we need to recognize quic first.
To do so, we can add ports for detection with probing parser in suricata.yaml configuration.
Or we need to modify suricata code, to add a fixed pattern like | 00 00 00 01| | at offset 1 (which can be followed by a probing parser to check)