# Resolution od stored images

**URL:** <https://forum.suricata.io/t/resolution-od-stored-images/2399>\
**Category:** Help\
**Tags:** suricata\
**Created:** [April 14, 2022, 7:31am UTC](https://forum.suricata.io/t/resolution-od-stored-images/2399 "2022-04-14T07:31:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mariusz](https://avatars.discourse-cdn.com/v4/letter/m/838e76/32.png) [@Mariusz](https://forum.suricata.io/u/Mariusz)\
**Post date:** [April 14, 2022, 7:31am UTC](https://forum.suricata.io/t/resolution-od-stored-images/2399/1 "2022-04-14T07:31:27Z")

</div>

Hello  
in our rules we have rule:  
pass http any any → any any (msg:“IMAGE”; http\_content\_type; content:“image”; filestore; sid:1;)

now question is … how i can modify this kind of rules to store only images that are “as normal” images. For examples → this kind of rules also store favicon. It is possible to define minimal resolution do store in filestore this images?

---

<div class="post-metadata">

**Author:** ![satta](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/satta/32/18_2.png) [@satta](https://forum.suricata.io/u/satta)\
**Post date:** [April 14, 2022, 8:19am UTC](https://forum.suricata.io/t/resolution-od-stored-images/2399/2 "2022-04-14T08:19:36Z")

</div>

You could use multiple rules, not just one for `image` but various specific ones, for each in the [Media Types](https://www.iana.org/assignments/media-types/media-types.xhtml#image) – excluding those you don’t want, i.e. `image/vnd.microsoft.icon` or `image/x-icon` for favicons. Since the rule as it is just looks at the HTTP header, not at the body, you won’t be able to select on file format-specific properties like resolution or image size.  
You might be able to use the HTTP content length header (Suricata buffer `http.content_len`) though to filter transfers that are “too small”. See [6.12. HTTP Keywords — Suricata 6.0.4 documentation](https://suricata.readthedocs.io/en/suricata-6.0.4/rules/http-keywords.html#http-content-len)
