Seems like there quite a few who know snort well here and Im hoping I can get an answere here faster than the snort mailing list ....
Stream4:
Ok so supposedly this reassembles a tcp stream. So a single email being sent should all be reassembled?
Basically some rules I developed scan for 2 parts of content in an email one at the begining and one at the end. Since the email will be large generally it will be sent in multiple packets. If I scan for the content seperatly both rules would trigger. But when I combine them into 1 rule with stream4 reassemble on it does not alert. Am I missing something?