Snort analyze reply based on request

I’m trying to write a snort rule which detects if certain binary files where requested via HTTP based on a regex rule matching there names. But it should only send an alert if the file exists (e.g. HTTP 200 OK reply).

Is it possible to have this kind of “statefull” scan? What kind of technique could I use else since the files have no reliable information in them I could search for.

The current look of my rule:

alert TCP $  EXTERNAL_NET any -> $  HOME_NET $  HTTP_PORTS (pcre:"/\d{6}-\d\.\d\.pdf$  /U"; sid:90000512; classtype:patent-access;)