A FILE rule's content check. Every condition set must hold. Pattern checks need the path sensor to collect contents; when the collected contents were cut short, a pattern that isn't found proves nothing and the file keeps its current findings. Patterns use RE2 syntax limited to ASCII: they can't name a character beyond ASCII or use a \p or \P class, though . and \S still match any character.
Fields
| Field Name | Description |
|---|---|
mustMatch - String
|
A regular expression (RE2 syntax) the collected contents must match. |
mustNotMatch - String
|
A regular expression (RE2 syntax) the collected contents must not match. |
checksum - String
|
The xxh3-128 checksum, as 32 hex characters, the file must have: the digest path sensors collect. |
Used by
RuleBodyFiletype: The body of a FILE rule.RuleFileContentsInputinput: Input variant of RuleFileContents.
Example
Example
{
"mustMatch": "abc123",
"mustNotMatch": "abc123",
"checksum": "xyz789"
}