b00e1772b3
rule logic should be endswith. match zeek fields for `fields` section add false positive information
rule logic should be endswith. match zeek fields for `fields` section add false positive information