1. Inspect the sample traffic shown on the page. The malicious request contains ' OR '1'='1 while benign requests do not.
2. Submit a rule such as:
alert tcp any any -> any any (msg:"SQLi"; content:"' OR '1'='1"; sid:1001;).
Why: the IDS checks whether your content: substring appears in the malicious payload and is absent from benign ones. A unique attack substring blocks the attack without false positives.
3. A correct, selective rule returns the flag. (Matching benign traffic too = rejected.)
Lesson: good signatures are specific to the attack, minimizing false positives.