# Rule using http does not matching get request

**URL:** <https://forum.suricata.io/t/rule-using-http-does-not-matching-get-request/2121>\
**Category:** Rules\
**Created:** [January 13, 2022, 9:31pm UTC](https://forum.suricata.io/t/rule-using-http-does-not-matching-get-request/2121 "2022-01-13T21:31:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![enag11](https://avatars.discourse-cdn.com/v4/letter/e/3be4f8/32.png) [@enag11](https://forum.suricata.io/u/enag11)\
**Post date:** [January 13, 2022, 9:31pm UTC](https://forum.suricata.io/t/rule-using-http-does-not-matching-get-request/2121/1 "2022-01-13T21:31:01Z")

</div>

Running Suricata 6.0.3 as an IPS gateway.  
NFQueue support: yes  
iptables -A FORWARD -j NFQUEUE  
starting suricata using:  
/usr/bin/suricata -v -q 0 -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid

Generating the request using curl: curl [http://myubd1.test75.com/page1](http://myubd1.test75.com/page1)

I’ve read through the similar topics but could not correct the problem

Trying to understand when I can use http in the rule or if my setup is incorrect.  
Is http only for IDS? The suricata.yaml shows  
libhtp:  
default-config:  
personality: IDS

I striped the rule to the bare basic  
alert http any any → any any (msg:“Rule 2”; rev:10; sid:2;) does not alert

alert tcp any any → any any (msg:“Rule 2”; rev:10; sid:2;) alerts  
01/13/2022-16:54:57.051779 [**] [1:2:10] Rule 2 [**] [Classification: (null)] [Priority: 3] {TCP} 10.12.1.2.1.75:80

Also tried using tcp protocol with an http keyword  
alert tcp any any → any any (msg:“Rule 2”; content:“[myubd1.test75.com/page1](http://myubd1.test75.com/page1)”; http\_uri; rev:10; sid:2;) - does not alert

---

<div class="post-metadata">

**Author:** ![Jungho](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jungho/32/397_2.png) [@Jungho](https://forum.suricata.io/u/Jungho)\
**Post date:** [January 14, 2022, 11:54am UTC](https://forum.suricata.io/t/rule-using-http-does-not-matching-get-request/2121/2 "2022-01-14T11:54:02Z")

</div>

You must distinguish between Host and URI in the address.

> alert tcp any any → any any (msg:“Rule 2”; content:“[myubd1.test75.com](http://myubd1.test75.com)”; http\_host; content:“/page1”; http\_uri; rev:10; sid:2; )

---

<div class="post-metadata">

**Author:** ![enag11](https://avatars.discourse-cdn.com/v4/letter/e/3be4f8/32.png) [@enag11](https://forum.suricata.io/u/enag11)\
**Post date:** [January 18, 2022, 4:38pm UTC](https://forum.suricata.io/t/rule-using-http-does-not-matching-get-request/2121/3 "2022-01-18T16:38:35Z")

</div>

Thanks for the response. I tried the suggested rule change and still do not get the alert
