i want to know where i have to chane the rule
ex: alert tcp any any -> $HOME_NET 9389 (msg:"SS POLICY Active Directory Web Services"; flow:to_server,established; flags:PA; content:"/ActiveDirectoryWebServices/Windows/Enumeration"; classtype:attempted-recon; sid:1000001;) where i have to write exactly
alert tcp any any -> any any (msg:"Feature1"; content:"#JN1"; nocase;
how to get this
05/-22:56:55.056993 [] [1:2019:0] Feature1 [] [Priority: 0] {TCP}
46.20.153.125:80 -> 10.0.2.15:56216
how to get message of Feature1