Rules with keyword and DNS resolution?

I was experimenting with some rules, and I noticed that a rule will not trigger if a isn’t resolvable.

For example:

alert http any any -> any any ( msg: "test";; content: ""; ) will not trigger while
alert http any any -> any any ( msg: "test";; content: ""; ) will.

Is there someplace I can disable this behavior so that when I provide a PCAP for analysis it won’t require the domain ( for example) to be resolvable?

Hi Jared,

Suricata does not do any DNS resolution itself. With those rules above, Suricata is parsing out the “Host” header from the HTTP traffic in the PCAP file and matches the content on that. No network activity is created by this process and could be done completely offline.

The PCAPs i was evaluating had HTTP.Requests using just LineFeeds, not CarriageReturn LineFeeds as HTTP specifies.