mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 10:08:20 +00:00
Some script reorg and a new intel extension script.
- policy/frameworks/intel/seen is the new location for the scripts that push data into the intel framework for checking. - The new policy/frameworks/intel/do_notice script adds an example mechanism for data driven notices.
This commit is contained in:
parent
d380161244
commit
32f1c736f7
15 changed files with 67 additions and 24 deletions
|
@ -63,9 +63,6 @@ export {
|
|||
IN_ANYWHERE,
|
||||
};
|
||||
|
||||
## The $host field and combination of $str and $str_type fields are mutually
|
||||
## exclusive. These records *must* represent either an IP address being
|
||||
## seen or a string being seen.
|
||||
type Seen: record {
|
||||
## The string if the data is about a string.
|
||||
indicator: string &log &optional;
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue