intel/seen/manage-event-groups: Policy script for toggling intel event groups

Co-authored-by: Mohan Dhawan <mohan@corelight.com>
This commit is contained in:
Arne Welzel 2025-05-15 09:34:14 +02:00
parent 7eb849ddf4
commit 0619fe2f4f
8 changed files with 285 additions and 0 deletions

View file

@ -17,6 +17,11 @@ redef DPD::track_removed_services_in_connection=T;
redef LogAscii::use_json = F;
@endif
# The tests don't load intel data and so all Intel event groups are disabled
# due to intel/seen/manage-event-groups being loaded by default. Disable that
# functionality by default to cover execution in the intel/seen scripts.
redef Intel::manage_seen_event_groups = F;
# The IMAP analyzer includes absolute filenames in its error messages,
# exclude it for now from analyzer.log.
# https://github.com/zeek/zeek/issues/2659