On Mon, 17 Sep 2018 16:33:53 +0000 (UTC) Pedro David Marco wrote: > > > On Monday, September 17, 2018, 6:29:33 PM GMT+2, RW > <rwmailli...@googlemail.com> wrote: > >If that actually occurred in the body it would be normalized to > >apache apache apache > > > >If you mean >apache > > > >apache > > > >apache>then my understanding is that a body rule would run > >apache>independently oneach instance of 'apache', not on > >apache>'apache\napache\napache\n'. > > Yes you are right... the question is how to "regex" along different > paragraphs...
You can sometimes work around it with rawbody rules. I don't know why body rules work that way. If the normalized body were stored as single-line paragraphs separated by newlines (perhaps broken into large blocks), it would make make it possible to write more reliable body rules without changing the behaviour of existing rules.