From 000cc5081316b83757ed8569caed2f5af4760d69 Mon Sep 17 00:00:00 2001 From: Arne Welzel Date: Mon, 19 May 2025 18:09:46 +0200 Subject: [PATCH] btest/core: Add event-trace test --- .../btest/Baseline/core.event-trace/.stderr | 1 + testing/btest/core/event-trace.zeek | 21 +++++++++++++++++++ 2 files changed, 22 insertions(+) create mode 100644 testing/btest/Baseline/core.event-trace/.stderr create mode 100644 testing/btest/core/event-trace.zeek diff --git a/testing/btest/Baseline/core.event-trace/.stderr b/testing/btest/Baseline/core.event-trace/.stderr new file mode 100644 index 0000000000..49d861c74c --- /dev/null +++ b/testing/btest/Baseline/core.event-trace/.stderr @@ -0,0 +1 @@ +### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63. diff --git a/testing/btest/core/event-trace.zeek b/testing/btest/core/event-trace.zeek new file mode 100644 index 0000000000..eeeeef61b7 --- /dev/null +++ b/testing/btest/core/event-trace.zeek @@ -0,0 +1,21 @@ +# @TEST-DOC: Verify the --event-trace feature works and produces the same logs as when reading from a pcap. +# +# Trace files produced with ZAM don't work - issue #4478 +# +# @TEST-REQUIRES: test "${ZEEK_ZAM}" != "1" +# +# @TEST-EXEC: zeek --event-trace trace.zeek -b -r $TRACES/http/get.trace %INPUT +# @TEST-EXEC: mkdir pcap-logs +# @TEST-EXEC: zeek-cut -m < http.log > pcap-logs/http.log +# @TEST-EXEC: rm -v *.log +# +# @TEST-EXEC: zeek -b --parse-only %INPUT trace.zeek +# @TEST-EXEC: zeek -b %INPUT trace.zeek +# @TEST-EXEC: mkdir trace-logs +# @TEST-EXEC: zeek-cut -m < http.log > trace-logs/http.log +# @TEST-EXEC: rm -v *.log +# +# @TEST-EXEC: diff pcap-logs/http.log trace-logs/http.log +# @TEST-EXEC: btest-diff .stderr + +@load base/protocols/http