diff --git a/test/falco_tests.yaml.in b/test/falco_tests.yaml.in index 17e61f24..77d15b8e 100644 --- a/test/falco_tests.yaml.in +++ b/test/falco_tests.yaml.in @@ -61,6 +61,13 @@ trace_files: !mux - repeated_evttypes_with_separate_in: [open] - repeated_evttypes_with_mix: [open] + rule_names_with_spaces: + detect: True + detect_level: WARNING + rules_file: + - rules/rule_names_with_spaces.yaml + trace_file: trace_files/cat_write.scap + multiple_rules_first_empty: detect: True detect_level: WARNING diff --git a/test/rules/rule_names_with_spaces.yaml b/test/rules/rule_names_with_spaces.yaml new file mode 100644 index 00000000..c4b8488e --- /dev/null +++ b/test/rules/rule_names_with_spaces.yaml @@ -0,0 +1,8 @@ +- macro: is_cat + condition: proc.name=cat + +- rule: Open From Cat + desc: A process named cat does an open + condition: evt.type=open and is_cat + output: "An open was seen (command=%proc.cmdline)" + priority: WARNING \ No newline at end of file