mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00
Updating some intel framework test baselines.
This commit is contained in:
parent
bf9651b323
commit
73f2fd8e3a
5 changed files with 30 additions and 0 deletions
|
@ -0,0 +1,2 @@
|
||||||
|
cluster_new_item: 123.123.123.123 inserted by worker-1 (from peer: worker-1)
|
||||||
|
cluster_new_item: 4.3.2.1 inserted by worker-2 (from peer: worker-2)
|
|
@ -0,0 +1,10 @@
|
||||||
|
#separator \x09
|
||||||
|
#set_separator ,
|
||||||
|
#empty_field (empty)
|
||||||
|
#unset_field -
|
||||||
|
#path intel
|
||||||
|
#open 2012-10-03-20-20-39
|
||||||
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p seen.host seen.str seen.str_type seen.where sources
|
||||||
|
#types time string addr port addr port addr string enum enum table[string]
|
||||||
|
1349295639.424940 - - - - - 123.123.123.123 - - Intel::IN_ANYWHERE worker-1
|
||||||
|
#close 2012-10-03-20-20-49
|
|
@ -0,0 +1,3 @@
|
||||||
|
cluster_new_item: 1.2.3.4 inserted by manager (from peer: manager-1)
|
||||||
|
cluster_new_item: 123.123.123.123 inserted by worker-1 (from peer: manager-1)
|
||||||
|
cluster_new_item: 4.3.2.1 inserted by worker-2 (from peer: manager-1)
|
|
@ -0,0 +1,4 @@
|
||||||
|
cluster_new_item: 1.2.3.4 inserted by manager (from peer: manager-1)
|
||||||
|
cluster_new_item: 123.123.123.123 inserted by worker-1 (from peer: manager-1)
|
||||||
|
cluster_new_item: 4.3.2.1 inserted by worker-2 (from peer: manager-1)
|
||||||
|
Doing a lookup
|
|
@ -0,0 +1,11 @@
|
||||||
|
#separator \x09
|
||||||
|
#set_separator ,
|
||||||
|
#empty_field (empty)
|
||||||
|
#unset_field -
|
||||||
|
#path intel
|
||||||
|
#open 2012-10-03-20-18-05
|
||||||
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p seen.host seen.str seen.str_type seen.where sources
|
||||||
|
#types time string addr port addr port addr string enum enum table[string]
|
||||||
|
1349295485.114156 - - - - - - e@mail.com Intel::EMAIL SOMEWHERE source1
|
||||||
|
1349295485.114156 - - - - - 1.2.3.4 - - SOMEWHERE source1
|
||||||
|
#close 2012-10-03-20-18-05
|
Loading…
Add table
Add a link
Reference in a new issue