mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Merge remote-tracking branch 'origin/topic/awelzel/3935-dce-rpc-named-pipe-docs'
* origin/topic/awelzel/3935-dce-rpc-named-pipe-docs: dce-rpc: Make named_pipe filed docs extensive
This commit is contained in:
commit
73d56407b1
3 changed files with 19 additions and 1 deletions
6
CHANGES
6
CHANGES
|
@ -1,3 +1,9 @@
|
||||||
|
8.0.0-dev.770 | 2025-07-28 14:18:15 -0700
|
||||||
|
|
||||||
|
* dce-rpc: Make named_pipe filed docs extensive (Arne Welzel, Corelight)
|
||||||
|
|
||||||
|
Closes #3935
|
||||||
|
|
||||||
8.0.0-dev.768 | 2025-07-28 14:16:16 -0700
|
8.0.0-dev.768 | 2025-07-28 14:16:16 -0700
|
||||||
|
|
||||||
* Fix parsing of EDNS rcode (Johanna Amann, Corelight)
|
* Fix parsing of EDNS rcode (Johanna Amann, Corelight)
|
||||||
|
|
2
VERSION
2
VERSION
|
@ -1 +1 @@
|
||||||
8.0.0-dev.768
|
8.0.0-dev.770
|
||||||
|
|
|
@ -21,6 +21,18 @@ export {
|
||||||
rtt : interval &log &optional;
|
rtt : interval &log &optional;
|
||||||
|
|
||||||
## Remote pipe name.
|
## Remote pipe name.
|
||||||
|
##
|
||||||
|
## Note that this value is from the "sec_addr" field in the
|
||||||
|
## protocol. Zeek uses the "named_pipe" name for historical reasons,
|
||||||
|
## but it may also contain local port numbers rather than named pipes.
|
||||||
|
##
|
||||||
|
## If you prefer to use the "secondary address" name, consider
|
||||||
|
## using :zeek:see:`Log::default_field_name_map`, a ``Log::Filter``'s
|
||||||
|
## :zeek:field:`Log::Filter$field_name_map` field, or removing
|
||||||
|
## the :zeek:attr:`&log` attribute from this field, adding a
|
||||||
|
## new :zeek:field:`sec_addr` field and populating it in a custom
|
||||||
|
## :zeek:see:`dce_rpc_bind_ack` event handler based on the
|
||||||
|
## :zeek:field:`named_pipe` value.
|
||||||
named_pipe : string &log &optional;
|
named_pipe : string &log &optional;
|
||||||
## Endpoint name looked up from the uuid.
|
## Endpoint name looked up from the uuid.
|
||||||
endpoint : string &log &optional;
|
endpoint : string &log &optional;
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue