Is port 8080 within your stream and http preprocessors?
Can you share the pcap?
Cisco Systems Inc.
I have a situation where snort does not appear to be recognizing packets that I have in a PCAP. The packet in question is a simple HTTP server response. The rule is setup to read content in the packet.
The server port is 8080. At this point, I can not figure out which configuration setting to change to get snort to parse the server response.
alert tcp any any -> any any \
msg: "Alert"; \
sid:6000002; rev:1; \