mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
testing/mysql: Add traces recorded with a free-tier MySQL instance
Not sure this adds much more coverage then there was, but minimally more recent software versions. The instances/passwords were ephemeral, so hostname and password hashes etc aren't useful to anyone.
This commit is contained in:
parent
672602dae7
commit
03dc21a861
8 changed files with 62 additions and 0 deletions
|
@ -0,0 +1,11 @@
|
||||||
|
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||||
|
#separator \x09
|
||||||
|
#set_separator ,
|
||||||
|
#empty_field (empty)
|
||||||
|
#unset_field -
|
||||||
|
#path conn
|
||||||
|
#open XXXX-XX-XX-XX-XX-XX
|
||||||
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig local_resp missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||||
|
#types time string addr port addr port enum string interval count count string bool bool count string count count count count set[string]
|
||||||
|
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 82.239.87.25 58132 79.107.90.25 3306 tcp - 2.043921 724 3255 SF - - 0 ShAdDaFf 14 1460 11 3835 -
|
||||||
|
#close XXXX-XX-XX-XX-XX-XX
|
|
@ -0,0 +1,11 @@
|
||||||
|
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||||
|
#separator \x09
|
||||||
|
#set_separator ,
|
||||||
|
#empty_field (empty)
|
||||||
|
#unset_field -
|
||||||
|
#path conn
|
||||||
|
#open XXXX-XX-XX-XX-XX-XX
|
||||||
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig local_resp missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||||
|
#types time string addr port addr port enum string interval count count string bool bool count string count count count count set[string]
|
||||||
|
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 82.239.87.25 57902 79.107.90.25 3306 tcp - 6.756360 1076 3776 SF - - 0 ShAdDaFf 19 2072 14 4512 -
|
||||||
|
#close XXXX-XX-XX-XX-XX-XX
|
|
@ -0,0 +1,14 @@
|
||||||
|
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||||
|
#separator \x09
|
||||||
|
#set_separator ,
|
||||||
|
#empty_field (empty)
|
||||||
|
#unset_field -
|
||||||
|
#path mysql
|
||||||
|
#open XXXX-XX-XX-XX-XX-XX
|
||||||
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p cmd arg success rows response
|
||||||
|
#types time string addr port addr port string string bool count string
|
||||||
|
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 82.239.87.25 58514 79.107.90.25 3306 login admin T 0 -
|
||||||
|
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 82.239.87.25 58514 79.107.90.25 3306 query select @@version_comment limit 1 T 0 -
|
||||||
|
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 82.239.87.25 58514 79.107.90.25 3306 query select now() T 0 -
|
||||||
|
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 82.239.87.25 58514 79.107.90.25 3306 quit (empty) - - -
|
||||||
|
#close XXXX-XX-XX-XX-XX-XX
|
BIN
testing/btest/Traces/mysql/plain-amazon-rds.trace
Normal file
BIN
testing/btest/Traces/mysql/plain-amazon-rds.trace
Normal file
Binary file not shown.
BIN
testing/btest/Traces/mysql/tls-12-amazon-rds.trace
Normal file
BIN
testing/btest/Traces/mysql/tls-12-amazon-rds.trace
Normal file
Binary file not shown.
BIN
testing/btest/Traces/mysql/tls-13-amazon-rds.trace
Normal file
BIN
testing/btest/Traces/mysql/tls-13-amazon-rds.trace
Normal file
Binary file not shown.
|
@ -0,0 +1,19 @@
|
||||||
|
# Just two traces with MySQL running in Amazon RDS tls1.3 and tls1.2
|
||||||
|
|
||||||
|
# @TEST-EXEC: zeek -b -r $TRACES/mysql/tls-12-amazon-rds.trace %INPUT
|
||||||
|
# @TEST-EXEC: mkdir tls-12 && mv *log tls-12
|
||||||
|
#
|
||||||
|
# @TEST-EXEC: zeek -b -r $TRACES/mysql/tls-13-amazon-rds.trace %INPUT
|
||||||
|
# @TEST-EXEC: mkdir tls-13 && mv *log tls-13
|
||||||
|
#
|
||||||
|
# @TEST-EXEC: btest-diff tls-12/conn.log
|
||||||
|
# #TEST-EXEC: btest-diff tls-12/ssl.log
|
||||||
|
# #TEST-EXEC: btest-diff tls-12/x509.log
|
||||||
|
#
|
||||||
|
# @TEST-EXEC: btest-diff tls-13/conn.log
|
||||||
|
# #TEST-EXEC: btest-diff tls-13/ssl.log
|
||||||
|
# #TEST-EXEC: ! test -f tls-13/x509.log
|
||||||
|
|
||||||
|
@load base/protocols/conn
|
||||||
|
@load base/protocols/mysql
|
||||||
|
@load base/protocols/ssl
|
|
@ -0,0 +1,7 @@
|
||||||
|
# Running with mysql --skip-ssl...
|
||||||
|
|
||||||
|
# @TEST-EXEC: zeek -b -r $TRACES/mysql/plain-amazon-rds.trace %INPUT
|
||||||
|
#
|
||||||
|
# @TEST-EXEC: btest-diff mysql.log
|
||||||
|
|
||||||
|
@load base/protocols/mysql
|
Loading…
Add table
Add a link
Reference in a new issue