Suricata dataset keywords

Hí,

We are used to seeing examples of dataset rule configuration with the keywords http.host, dns.query …
What other keywords can we use?

Can we use for example sip.uri or ssh.software?

Greetings,

Yes, it can be used on any sticky buffer

1 Like

Hi,

Thank you so much.