mirror of
https://github.com/zeek/zeek.git
synced 2025-10-15 04:58:21 +00:00
Initial move of zeek-aux btests and related files to zeek btest dir
This commit is contained in:
parent
c05da53275
commit
7887451a66
148 changed files with 0 additions and 0 deletions
|
@ -0,0 +1,5 @@
|
|||
## #BTest baseline data generated by btest - diff.Do not edit.Use "btest -U/-u" to update.Requires BTest >= 0.63.
|
||||
#define ZEEK_VERSION "1.0.0-2" /* with comment */
|
||||
#define ZEEK_VERSION "1.0.0-2" /* with comment */
|
||||
#define FOO_VERSION "1.0.0-2" // another comment
|
||||
...
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
__version__ = "1.0.0.dev2", # with comment
|
||||
__version__ = "1.0.0.dev2", # another comment
|
||||
__version__ = "1.0.0.dev2", # Python style
|
||||
__version__ = "0.0.1.nope" # should not change
|
||||
version = "0.0.1" # should not change
|
||||
print('Additional change')
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
.. |version| replace:: 1.0.0-2
|
||||
.. |version| replace:: 1.0.0-2
|
||||
.. |version| replace:: 1.0.0-2
|
||||
.. |version| replace:: 1.0.0-2
|
||||
.. |version| replace:: 1.0.0-2
|
||||
...
|
|
@ -0,0 +1,8 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
VERSION="1.0.0-2"
|
||||
VERSION="1.0.0-2"
|
||||
VERSION="1.0.0-2"
|
||||
VERSION="1.0.0-2"
|
||||
VERSION = "1.0.0-2" # with some comment
|
||||
VERSION = "2.0.0-nope" # with some comment
|
||||
...
|
|
@ -0,0 +1,8 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
version = "1.0.0.dev2", # short
|
||||
version = "1.0.0.dev2", # with dev update
|
||||
version = "1.0.0.dev2", # long
|
||||
version = "1.0.0.dev2", # long with dev update
|
||||
version = "1.0.0.dev2", # Python style
|
||||
version = "0.0.1.nope" # should not change, invalid suffix
|
||||
print('Additional change')
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
zeek-cut: bad log header (missing #fields line)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
CjhGID4nQcgTWjvg4c tcp
|
||||
CCvvfg3TEfuqmmG4bh tcp
|
||||
CsRx2w45OKnoww6xl4 tcp
|
||||
CRJuHdVW0XPVINV8a tcp
|
||||
CXWv6p3arKYeMETxOg tcp
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
zeek-cut: bad log header (invalid #separator line)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
zeek-cut: bad log header (invalid #separator line)
|
7
testing/btest/Baseline/zeek-aux.zeek-cut.columns/all
Normal file
7
testing/btest/Baseline/zeek-aux.zeek-cut.columns/all
Normal file
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329327783.316897 CjhGID4nQcgTWjvg4c 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 CCvvfg3TEfuqmmG4bh 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 CsRx2w45OKnoww6xl4 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 CRJuHdVW0XPVINV8a 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 CXWv6p3arKYeMETxOg 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 CPbrpk1qSsw6ESzHV4 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,11 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg
|
|
@ -0,0 +1,11 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
tcp CjhGID4nQcgTWjvg4c
|
||||
tcp CCvvfg3TEfuqmmG4bh
|
||||
tcp CsRx2w45OKnoww6xl4
|
||||
tcp CRJuHdVW0XPVINV8a
|
||||
tcp CXWv6p3arKYeMETxOg
|
||||
tcp,CNbXUV0IZ29or3MK6
|
||||
tcp,CJ8woc3c6CfBLdiyp5
|
||||
tcp,CXlgj54ftP8Yc2GSnb
|
||||
tcp,Czw8Gd1zEVn3Xz5x7i
|
||||
tcp,Cys4aQ15qDqHzsIk3l
|
6
testing/btest/Baseline/zeek-aux.zeek-cut.columns/one
Normal file
6
testing/btest/Baseline/zeek-aux.zeek-cut.columns/one
Normal file
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
CjhGID4nQcgTWjvg4c
|
||||
CCvvfg3TEfuqmmG4bh
|
||||
CsRx2w45OKnoww6xl4
|
||||
CRJuHdVW0XPVINV8a
|
||||
CXWv6p3arKYeMETxOg
|
|
@ -0,0 +1,12 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
CjhGID4nQcgTWjvg4c tcp
|
||||
CCvvfg3TEfuqmmG4bh tcp
|
||||
CsRx2w45OKnoww6xl4 tcp
|
||||
CRJuHdVW0XPVINV8a tcp
|
||||
CXWv6p3arKYeMETxOg tcp
|
||||
CjhGID4nQcgTWjvg4c
|
||||
CCvvfg3TEfuqmmG4bh
|
||||
CsRx2w45OKnoww6xl4
|
||||
CRJuHdVW0XPVINV8a
|
||||
CXWv6p3arKYeMETxOg
|
||||
CPbrpk1qSsw6ESzHV4
|
|
@ -0,0 +1,12 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
CjhGID4nQcgTWjvg4c
|
||||
CCvvfg3TEfuqmmG4bh
|
||||
CsRx2w45OKnoww6xl4
|
||||
CRJuHdVW0XPVINV8a
|
||||
CXWv6p3arKYeMETxOg
|
||||
CPbrpk1qSsw6ESzHV4
|
||||
CjhGID4nQcgTWjvg4c tcp
|
||||
CCvvfg3TEfuqmmG4bh tcp
|
||||
CsRx2w45OKnoww6xl4 tcp
|
||||
CRJuHdVW0XPVINV8a tcp
|
||||
CXWv6p3arKYeMETxOg tcp
|
2
testing/btest/Baseline/zeek-aux.zeek-cut.columns/only
Normal file
2
testing/btest/Baseline/zeek-aux.zeek-cut.columns/only
Normal file
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
79.26.245.236
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
tcp CjhGID4nQcgTWjvg4c
|
||||
tcp CCvvfg3TEfuqmmG4bh
|
||||
tcp CsRx2w45OKnoww6xl4
|
||||
tcp CRJuHdVW0XPVINV8a
|
||||
tcp CXWv6p3arKYeMETxOg
|
25
testing/btest/Baseline/zeek-aux.zeek-cut.help/show-help
Normal file
25
testing/btest/Baseline/zeek-aux.zeek-cut.help/show-help
Normal file
|
@ -0,0 +1,25 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
zeek-cut [options] [<columns>]
|
||||
|
||||
Extracts the given columns from ASCII Zeek logs on standard input, and outputs
|
||||
them to standard output. If no columns are given, all are selected.
|
||||
By default, zeek-cut does not include format header blocks in the output.
|
||||
|
||||
Example: cat conn.log | zeek-cut -d ts id.orig_h id.orig_p
|
||||
|
||||
-c Include the first format header block in the output.
|
||||
-C Include all format header blocks in the output.
|
||||
-m Include the first format header blocks in the output in minimal view.
|
||||
-M Include all format header blocks in the output in minimal view.
|
||||
-d Convert time values into human-readable format.
|
||||
-D <fmt> Like -d, but specify format for time (see strftime(3) for syntax).
|
||||
-F <ofs> Sets a different output field separator character.
|
||||
-h Show help.
|
||||
-n Print all fields *except* those specified.
|
||||
-u Like -d, but print timestamps in UTC instead of local time.
|
||||
-U <fmt> Like -D, but print timestamps in UTC instead of local time.
|
||||
|
||||
For time conversion option -d or -u, the format string can be specified by
|
||||
setting an environment variable ZEEK_CUT_TIMEFMT.
|
||||
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,20 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,14 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents ts
|
||||
CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty) 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty) 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty) 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty) 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty) 1329843161.968492
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
ts uid
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg
|
||||
ts uid
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
proto uid
|
||||
tcp CjhGID4nQcgTWjvg4c
|
||||
tcp CCvvfg3TEfuqmmG4bh
|
||||
tcp CsRx2w45OKnoww6xl4
|
||||
tcp CRJuHdVW0XPVINV8a
|
||||
tcp CXWv6p3arKYeMETxOg
|
||||
proto,uid
|
||||
tcp,CNbXUV0IZ29or3MK6
|
||||
tcp,CJ8woc3c6CfBLdiyp5
|
||||
tcp,CXlgj54ftP8Yc2GSnb
|
||||
tcp,Czw8Gd1zEVn3Xz5x7i
|
||||
tcp,Cys4aQ15qDqHzsIk3l
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,13 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid,ts
|
||||
CjhGID4nQcgTWjvg4c,1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh,1329843179.871641
|
||||
CsRx2w45OKnoww6xl4,1329843194.151526
|
||||
CRJuHdVW0XPVINV8a,1329843197.783443
|
||||
CXWv6p3arKYeMETxOg,1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c,1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh,1329327786.524332
|
||||
CsRx2w45OKnoww6xl4,1329327787.289095
|
||||
CRJuHdVW0XPVINV8a,1329327795.571921
|
||||
CXWv6p3arKYeMETxOg,1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4,1329327800.017649
|
|
@ -0,0 +1,14 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
uid ts
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,14 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
uid,ts
|
||||
CjhGID4nQcgTWjvg4c,1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh,1329843179.871641
|
||||
CsRx2w45OKnoww6xl4,1329843194.151526
|
||||
CRJuHdVW0XPVINV8a,1329843197.783443
|
||||
CXWv6p3arKYeMETxOg,1329843161.968492
|
||||
uid,ts
|
||||
CjhGID4nQcgTWjvg4c,1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh,1329327786.524332
|
||||
CsRx2w45OKnoww6xl4,1329327787.289095
|
||||
CRJuHdVW0XPVINV8a,1329327795.571921
|
||||
CXWv6p3arKYeMETxOg,1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4,1329327800.017649
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
7
testing/btest/Baseline/zeek-aux.zeek-cut.no-options/tsv
Normal file
7
testing/btest/Baseline/zeek-aux.zeek-cut.no-options/tsv
Normal file
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,11 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329327783.316897 CjhGID4nQcgTWjvg4c 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 CCvvfg3TEfuqmmG4bh 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 CsRx2w45OKnoww6xl4 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 CRJuHdVW0XPVINV8a 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 CXWv6p3arKYeMETxOg 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 CPbrpk1qSsw6ESzHV4 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329327783.316897 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329327783.316897 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,15 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-15-51
|
||||
#fields ts id.orig_h id.orig_p id.resp_h
|
||||
#types time addr port addr
|
||||
1329327783.316897 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329327783.316897 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1329327783.316897 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186
|
||||
1329327786.524332 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187
|
||||
1329327787.289095 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188
|
||||
1329327795.571921 2001:470:4867:99::21 55785
|
||||
1329327777.822004 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185
|
||||
1329327800.017649 2001:470:4867:99::21 55647
|
|
@ -0,0 +1,11 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
tcp:CjhGID4nQcgTWjvg4c
|
||||
tcp:CCvvfg3TEfuqmmG4bh
|
||||
tcp:CsRx2w45OKnoww6xl4
|
||||
tcp:CRJuHdVW0XPVINV8a
|
||||
tcp:CXWv6p3arKYeMETxOg
|
||||
tcp:CNbXUV0IZ29or3MK6
|
||||
tcp:CJ8woc3c6CfBLdiyp5
|
||||
tcp:CXlgj54ftP8Yc2GSnb
|
||||
tcp:Czw8Gd1zEVn3Xz5x7i
|
||||
tcp:Cys4aQ15qDqHzsIk3l
|
2
testing/btest/Baseline/zeek-aux.zeek-cut.ofs/only-column
Normal file
2
testing/btest/Baseline/zeek-aux.zeek-cut.ofs/only-column
Normal file
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
79.26.245.236
|
14
testing/btest/Baseline/zeek-aux.zeek-cut.ofs/show-header
Normal file
14
testing/btest/Baseline/zeek-aux.zeek-cut.ofs/show-header
Normal file
|
@ -0,0 +1,14 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields.ts.uid.id.orig_h.id.orig_p.id.resp_h.id.resp_p.proto.service.duration.orig_bytes.resp_bytes.conn_state.local_orig.missed_bytes.history.orig_pkts.orig_ip_bytes.resp_pkts.resp_ip_bytes.tunnel_parents
|
||||
#types.time.string.addr.port.addr.port.enum.string.interval.count.count.string.bool.count.string.count.count.count.count.set[string]
|
||||
1329843175.736107.CjhGID4nQcgTWjvg4c.141.142.220.235.37604.199.233.217.249.56666.tcp.ftp-data.0.112432.0.342.SF.-.0.ShAdfFa.4.216.4.562.(empty)
|
||||
1329843179.871641.CCvvfg3TEfuqmmG4bh.141.142.220.235.59378.199.233.217.249.56667.tcp.ftp-data.0.111218.0.77.SF.-.0.ShAdfFa.4.216.4.297.(empty)
|
||||
1329843194.151526.CsRx2w45OKnoww6xl4.199.233.217.249.61920.141.142.220.235.33582.tcp.ftp-data.0.056211.342.0.SF.-.0.ShADaFf.5.614.3.164.(empty)
|
||||
1329843197.783443.CRJuHdVW0XPVINV8a.199.233.217.249.61918.141.142.220.235.37835.tcp.ftp-data.0.056005.77.0.SF.-.0.ShADaFf.5.349.3.164.(empty)
|
||||
1329843161.968492.CXWv6p3arKYeMETxOg.141.142.220.235.50003.199.233.217.249.21.tcp.ftp.38.055625.180.3146.SF.-.0.ShAdDfFa.38.2164.25.4458.(empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
CjhGID4nQcgTWjvg4c,1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh,1329843179.871641
|
||||
CsRx2w45OKnoww6xl4,1329843194.151526
|
||||
CRJuHdVW0XPVINV8a,1329843197.783443
|
||||
CXWv6p3arKYeMETxOg,1329843161.968492
|
|
@ -0,0 +1,30 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-15-51
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
||||
#close 2014-04-01-23-15-51
|
|
@ -0,0 +1,20 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,29 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
#types time string addr port addr port enum string interval count count string bool count string count count count count set[string]
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conntimelast
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents ts
|
||||
#types string addr port addr port enum string interval count count string bool count string count count count count set[string] time
|
||||
CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty) 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty) 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty) 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty) 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty) 1329843161.968492
|
||||
#close 2014-04-01-23-15-49
|
|
@ -0,0 +1,29 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts uid
|
||||
#types time string
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conntimelast
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts uid
|
||||
#types time string
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg
|
||||
#close 2014-04-01-23-15-49
|
|
@ -0,0 +1,29 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields proto uid
|
||||
#types enum string
|
||||
tcp CjhGID4nQcgTWjvg4c
|
||||
tcp CCvvfg3TEfuqmmG4bh
|
||||
tcp CsRx2w45OKnoww6xl4
|
||||
tcp CRJuHdVW0XPVINV8a
|
||||
tcp CXWv6p3arKYeMETxOg
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator ,
|
||||
#set_separator,,
|
||||
#empty_field,(empty)
|
||||
#unset_field,-
|
||||
#path,conn
|
||||
#open,2014-06-30-16-10-54
|
||||
#fields,proto,uid
|
||||
#types,enum,string
|
||||
tcp,CNbXUV0IZ29or3MK6
|
||||
tcp,CJ8woc3c6CfBLdiyp5
|
||||
tcp,CXlgj54ftP8Yc2GSnb
|
||||
tcp,Czw8Gd1zEVn3Xz5x7i
|
||||
tcp,Cys4aQ15qDqHzsIk3l
|
||||
#close,2014-06-30-16-10-55
|
|
@ -0,0 +1,14 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
#types time string addr port addr port enum string interval count count string bool count string count count count count set[string]
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,15 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
#types time string addr port addr port enum string interval count count string bool count string count count count count set[string]
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
#close 2014-04-01-23-15-49
|
|
@ -0,0 +1,20 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
|
@ -0,0 +1,30 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 1329843161.968492
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-15-51
|
||||
#fields uid ts
|
||||
#types string time
|
||||
CjhGID4nQcgTWjvg4c 1329327783.316897
|
||||
CCvvfg3TEfuqmmG4bh 1329327786.524332
|
||||
CsRx2w45OKnoww6xl4 1329327787.289095
|
||||
CRJuHdVW0XPVINV8a 1329327795.571921
|
||||
CXWv6p3arKYeMETxOg 1329327777.822004
|
||||
CPbrpk1qSsw6ESzHV4 1329327800.017649
|
||||
#close 2014-04-01-23-15-51
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
hello a
|
||||
-12345.123456 b
|
||||
77777777777777777777 c
|
||||
d
|
||||
123456789 e
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
zeek-cut: time field is not valid: hello
|
||||
zeek-cut: time value out-of-range: -12345.123456
|
||||
zeek-cut: time value out-of-range: 77777777777777777777
|
||||
zeek-cut: time field is not valid:
|
||||
zeek-cut: time field is not valid: 123456789
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
zeek-cut: bad log header (missing #types line)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2012-02-21T16:52:55+0000 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
2012-02-21T16:52:59+0000 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
2012-02-21T16:53:14+0000 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
2012-02-21T16:53:17+0000 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
2012-02-21T16:52:41+0000 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2012-02-21T08:52:55-0800 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
2012-02-21T08:52:59-0800 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
2012-02-21T08:53:14-0800 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
2012-02-21T08:53:17-0800 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
2012-02-21T08:52:41-0800 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,11 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2012-02-21T08:52:55-0800 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
2012-02-21T08:52:59-0800 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
2012-02-21T08:53:14-0800 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
2012-02-21T08:53:17-0800 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
2012-02-21T08:52:41-0800 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty) 2012-02-21T08:52:55-0800
|
||||
CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty) 2012-02-21T08:52:59-0800
|
||||
CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty) 2012-02-21T08:53:14-0800
|
||||
CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty) 2012-02-21T08:53:17-0800
|
||||
CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty) 2012-02-21T08:52:41-0800
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2012-02-21T08:52:55-0800 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
2012-02-21T08:52:59-0800 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
2012-02-21T08:53:14-0800 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
2012-02-21T08:53:17-0800 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
2012-02-21T08:52:41-0800 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
@ -0,0 +1,5 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2012-02-21T08:52:55-0800 tcp 2012-02-21T08:53:05-0800
|
||||
2012-02-21T08:52:59-0800 udp 2012-02-21T08:52:59-0800
|
||||
2012-02-21T08:53:14-0800 tcp 2012-02-21T08:53:24-0800
|
||||
2012-02-21T08:53:24-0800 tcp 2012-02-21T08:54:15-0800
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
79.26.245.236
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty) 2012-02-21T08:52:55-0800
|
||||
CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty) 2012-02-21T08:52:59-0800
|
||||
CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty) 2012-02-21T08:53:14-0800
|
||||
CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty) 2012-02-21T08:53:17-0800
|
||||
CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty) 2012-02-21T08:52:41-0800
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2012-02-21T16:52:55+0000 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
2012-02-21T16:52:59+0000 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
2012-02-21T16:53:14+0000 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
2012-02-21T16:53:17+0000 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
2012-02-21T16:52:41+0000 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,7 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1970-01-01T00:00:00+0000 CjhGID4nQcgTWjvg4c 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
2012-02-15T17:43:06+0000 CCvvfg3TEfuqmmG4bh 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
2012-02-15T17:43:07+0000 CsRx2w45OKnoww6xl4 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
2012-02-15T17:43:15+0000 CRJuHdVW0XPVINV8a 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
2012-02-15T17:42:57+0000 CXWv6p3arKYeMETxOg 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
2012-02-15T17:43:20+0000 CPbrpk1qSsw6ESzHV4 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
0852_120221 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
0852_120221 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
0853_120221 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
0853_120221 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
0852_120221 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
08 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
08 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
08 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
08 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
08 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1652_120221 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1652_120221 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1653_120221 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1653_120221 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1652_120221 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
16 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
16 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
16 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
16 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
16 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
08 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
08 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
08 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
08 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
08 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
16 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
16 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
16 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
16 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
16 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
16 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
16 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
16 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
16 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
16 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
16 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
16 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
16 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
16 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
16 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
08 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
08 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
08 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
08 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
08 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,6 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
08 52 12 02 21 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
08 52 12 02 21 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
08 53 12 02 21 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
08 53 12 02 21 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
08 52 12 02 21 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
|
@ -0,0 +1,29 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields proto ts id.orig_h
|
||||
#types enum string addr
|
||||
tcp 2012-02-21T08:52:55-0800 141.142.220.235
|
||||
tcp 2012-02-21T08:52:59-0800 141.142.220.235
|
||||
tcp 2012-02-21T08:53:14-0800 199.233.217.249
|
||||
tcp 2012-02-21T08:53:17-0800 199.233.217.249
|
||||
tcp 2012-02-21T08:52:41-0800 141.142.220.235
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conntimelast
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields proto ts id.orig_h
|
||||
#types enum string addr
|
||||
tcp 2012-02-21T08:52:55-0800 141.142.220.235
|
||||
tcp 2012-02-21T08:52:59-0800 141.142.220.235
|
||||
tcp 2012-02-21T08:53:14-0800 199.233.217.249
|
||||
tcp 2012-02-21T08:53:17-0800 199.233.217.249
|
||||
tcp 2012-02-21T08:52:41-0800 141.142.220.235
|
||||
#close 2014-04-01-23-15-49
|
|
@ -0,0 +1,29 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields proto ts id.orig_h
|
||||
#types enum string addr
|
||||
tcp 2012-02-21T08:52:55-0800 141.142.220.235
|
||||
tcp 2012-02-21T08:52:59-0800 141.142.220.235
|
||||
tcp 2012-02-21T08:53:14-0800 199.233.217.249
|
||||
tcp 2012-02-21T08:53:17-0800 199.233.217.249
|
||||
tcp 2012-02-21T08:52:41-0800 141.142.220.235
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator ,
|
||||
#set_separator,,
|
||||
#empty_field,(empty)
|
||||
#unset_field,-
|
||||
#path,conn
|
||||
#open,2014-06-30-16-10-54
|
||||
#fields,proto,ts,id.orig_h
|
||||
#types,enum,string,addr
|
||||
tcp,2012-02-21T08:52:55-0800,141.142.220.235
|
||||
tcp,2012-02-21T08:52:59-0800,141.142.220.235
|
||||
tcp,2012-02-21T08:53:14-0800,199.233.217.249
|
||||
tcp,2012-02-21T08:52:41-0800,141.142.220.235
|
||||
tcp,2012-02-21T08:53:17-0800,199.233.217.249
|
||||
#close,2014-06-30-16-10-55
|
|
@ -0,0 +1,25 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts id.orig_h
|
||||
#types string addr
|
||||
2012-02-21T08:52:55-0800 141.142.220.235
|
||||
2012-02-21T08:52:59-0800 141.142.220.235
|
||||
2012-02-21T08:53:14-0800 199.233.217.249
|
||||
2012-02-21T08:53:17-0800 199.233.217.249
|
||||
2012-02-21T08:52:41-0800 141.142.220.235
|
||||
#close 2014-04-01-23-15-49
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path onecolumn
|
||||
#open 2014-04-01-23-15-59
|
||||
#fields id.orig_h
|
||||
#types addr
|
||||
79.26.245.236
|
||||
#close 2014-04-01-23-15-59
|
|
@ -0,0 +1,14 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-16-29
|
||||
#fields proto ts2 ts1
|
||||
#types enum string string
|
||||
tcp 2012-02-21T08:53:05-0800 2012-02-21T08:52:55-0800
|
||||
udp 2012-02-21T08:52:59-0800 2012-02-21T08:52:59-0800
|
||||
tcp 2012-02-21T08:53:24-0800 2012-02-21T08:53:14-0800
|
||||
tcp 2012-02-21T08:54:15-0800 2012-02-21T08:53:24-0800
|
||||
#close 2014-04-01-23-16-29
|
|
@ -0,0 +1,15 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator ,
|
||||
#set_separator,,
|
||||
#empty_field,(empty)
|
||||
#unset_field,-
|
||||
#path,conn
|
||||
#open,2014-06-30-16-10-54
|
||||
#fields,proto,ts,id.orig_h
|
||||
#types,enum,string,addr
|
||||
tcp,2012-02-21T08:52:55-0800,141.142.220.235
|
||||
tcp,2012-02-21T08:52:59-0800,141.142.220.235
|
||||
tcp,2012-02-21T08:53:14-0800,199.233.217.249
|
||||
tcp,2012-02-21T08:52:41-0800,141.142.220.235
|
||||
tcp,2012-02-21T08:53:17-0800,199.233.217.249
|
||||
#close,2014-06-30-16-10-55
|
|
@ -0,0 +1,15 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts id.orig_h ts
|
||||
#types string addr string
|
||||
2012-02-21T08:52:55-0800 141.142.220.235 2012-02-21T08:52:55-0800
|
||||
2012-02-21T08:52:59-0800 141.142.220.235 2012-02-21T08:52:59-0800
|
||||
2012-02-21T08:53:14-0800 199.233.217.249 2012-02-21T08:53:14-0800
|
||||
2012-02-21T08:53:17-0800 199.233.217.249 2012-02-21T08:53:17-0800
|
||||
2012-02-21T08:52:41-0800 141.142.220.235 2012-02-21T08:52:41-0800
|
||||
#close 2014-04-01-23-15-49
|
16
testing/btest/Baseline/zeek-aux.zeek-cut.time-header/utc-fmt
Normal file
16
testing/btest/Baseline/zeek-aux.zeek-cut.time-header/utc-fmt
Normal file
|
@ -0,0 +1,16 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-15-51
|
||||
#fields ts uid id.orig_h id.orig_p id.resp_h
|
||||
#types string string addr port addr
|
||||
17 43 12 02 15 CjhGID4nQcgTWjvg4c 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
17 43 12 02 15 CCvvfg3TEfuqmmG4bh 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
17 43 12 02 15 CsRx2w45OKnoww6xl4 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
17 43 12 02 15 CRJuHdVW0XPVINV8a 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
17 42 12 02 15 CXWv6p3arKYeMETxOg 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
17 43 12 02 15 CPbrpk1qSsw6ESzHV4 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
#close 2014-04-01-23-15-51
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2015-04-21T02:34:05+0000 CXWv6p3arKYeMETxOg 192.168.1.31 64889 192.168.1.32 88 TGS user/TEST.NET krbtgt/TEST.NET T - - 1970-01-01T00:00:00+0000 aes256-cts-hmac-sha1-96 T F - - - -
|
|
@ -0,0 +1,2 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
2015-04-21T02:34:05+0000 CXWv6p3arKYeMETxOg 192.168.1.31 64889 192.168.1.32 88 TGS user/TEST.NET krbtgt/TEST.NET T (unset_test) (unset_test) 1970-01-01T00:00:00+0000 aes256-cts-hmac-sha1-96 T F (unset_test) (unset_test) (unset_test) (unset_test)
|
6
testing/btest/Files/zeek-aux-Logs/conn-tsv.log
Normal file
6
testing/btest/Files/zeek-aux-Logs/conn-tsv.log
Normal file
|
@ -0,0 +1,6 @@
|
|||
ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
1329843175.736107 CHUSyo3gjtvVLqrHGk 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CWMUpO2OZ5t5tLk6Hk 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CtII2N2AidtNJlD9f7 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843161.968492 CQyLvn3Dh4UDubXFRh 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
1329843197.783443 CuFJh714tTrtlGOxl7 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
14
testing/btest/Files/zeek-aux-Logs/conn.log
Normal file
14
testing/btest/Files/zeek-aux-Logs/conn.log
Normal file
|
@ -0,0 +1,14 @@
|
|||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conn
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
|
||||
#types time string addr port addr port enum string interval count count string bool count string count count count count set[string]
|
||||
1329843175.736107 CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty)
|
||||
1329843179.871641 CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty)
|
||||
1329843194.151526 CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty)
|
||||
1329843197.783443 CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty)
|
||||
1329843161.968492 CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty)
|
||||
#close 2014-04-01-23-15-49
|
14
testing/btest/Files/zeek-aux-Logs/conncomma.log
Normal file
14
testing/btest/Files/zeek-aux-Logs/conncomma.log
Normal file
|
@ -0,0 +1,14 @@
|
|||
#separator ,
|
||||
#set_separator,,
|
||||
#empty_field,(empty)
|
||||
#unset_field,-
|
||||
#path,conn
|
||||
#open,2014-06-30-16-10-54
|
||||
#fields,ts,uid,id.orig_h,id.orig_p,id.resp_h,id.resp_p,proto,service,duration,orig_bytes,resp_bytes,conn_state,local_orig,missed_bytes,history,orig_pkts,orig_ip_bytes,resp_pkts,resp_ip_bytes,tunnel_parents
|
||||
#types,time,string,addr,port,addr,port,enum,string,interval,count,count,string,bool,count,string,count,count,count,count,set[string]
|
||||
1329843175.736107,CNbXUV0IZ29or3MK6,141.142.220.235,37604,199.233.217.249,56666,tcp,ftp-data,0.112432,0,342,SF,-,0,ShAdfFa,4,216,4,562,(empty)
|
||||
1329843179.871641,CJ8woc3c6CfBLdiyp5,141.142.220.235,59378,199.233.217.249,56667,tcp,ftp-data,0.111218,0,77,SF,-,0,ShAdfFa,4,216,4,297,(empty)
|
||||
1329843194.151526,CXlgj54ftP8Yc2GSnb,199.233.217.249,61920,141.142.220.235,33582,tcp,ftp-data,0.056211,342,0,SF,-,0,ShADaFf,5,614,3,164,(empty)
|
||||
1329843161.968492,Czw8Gd1zEVn3Xz5x7i,141.142.220.235,50003,199.233.217.249,21,tcp,ftp,38.055625,180,3146,SF,-,0,ShAdDfFa,38,2164,25,4458,(empty)
|
||||
1329843197.783443,Cys4aQ15qDqHzsIk3l,199.233.217.249,61918,141.142.220.235,37835,tcp,ftp-data,0.056005,77,0,SF,-,0,ShADaFf,5,349,3,164,(empty)
|
||||
#close,2014-06-30-16-10-55
|
14
testing/btest/Files/zeek-aux-Logs/conntimelast.log
Normal file
14
testing/btest/Files/zeek-aux-Logs/conntimelast.log
Normal file
|
@ -0,0 +1,14 @@
|
|||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path conntimelast
|
||||
#open 2014-04-01-23-15-49
|
||||
#fields uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents ts
|
||||
#types string addr port addr port enum string interval count count string bool count string count count count count set[string] time
|
||||
CjhGID4nQcgTWjvg4c 141.142.220.235 37604 199.233.217.249 56666 tcp ftp-data 0.112432 0 342 SF - 0 ShAdfFa 4 216 4 562 (empty) 1329843175.736107
|
||||
CCvvfg3TEfuqmmG4bh 141.142.220.235 59378 199.233.217.249 56667 tcp ftp-data 0.111218 0 77 SF - 0 ShAdfFa 4 216 4 297 (empty) 1329843179.871641
|
||||
CsRx2w45OKnoww6xl4 199.233.217.249 61920 141.142.220.235 33582 tcp ftp-data 0.056211 342 0 SF - 0 ShADaFf 5 614 3 164 (empty) 1329843194.151526
|
||||
CRJuHdVW0XPVINV8a 199.233.217.249 61918 141.142.220.235 37835 tcp ftp-data 0.056005 77 0 SF - 0 ShADaFf 5 349 3 164 (empty) 1329843197.783443
|
||||
CXWv6p3arKYeMETxOg 141.142.220.235 50003 199.233.217.249 21 tcp ftp 38.055625 180 3146 SF - 0 ShAdDfFa 38 2164 25 4458 (empty) 1329843161.968492
|
||||
#close 2014-04-01-23-15-49
|
7
testing/btest/Files/zeek-aux-Logs/invalid-time.log
Normal file
7
testing/btest/Files/zeek-aux-Logs/invalid-time.log
Normal file
|
@ -0,0 +1,7 @@
|
|||
#fields ts test
|
||||
#types time string
|
||||
hello a
|
||||
-12345.123456 b
|
||||
77777777777777777777 c
|
||||
d
|
||||
123456789 e
|
3
testing/btest/Files/zeek-aux-Logs/missing-separator.log
Normal file
3
testing/btest/Files/zeek-aux-Logs/missing-separator.log
Normal file
|
@ -0,0 +1,3 @@
|
|||
#separator
|
||||
#fields a
|
||||
hi
|
13
testing/btest/Files/zeek-aux-Logs/multiple-times.log
Normal file
13
testing/btest/Files/zeek-aux-Logs/multiple-times.log
Normal file
|
@ -0,0 +1,13 @@
|
|||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-16-29
|
||||
#fields ts1 proto ts2
|
||||
#types time enum time
|
||||
1329843175.736107 tcp 1329843185.736107
|
||||
1329843179.871641 udp 1329843179.982531
|
||||
1329843194.151526 tcp 1329843204.151526
|
||||
1329843204.987656 tcp 1329843255.123456
|
||||
#close 2014-04-01-23-16-29
|
3
testing/btest/Files/zeek-aux-Logs/null-separator.log
Normal file
3
testing/btest/Files/zeek-aux-Logs/null-separator.log
Normal file
|
@ -0,0 +1,3 @@
|
|||
#separator \x00
|
||||
#fields a
|
||||
hi
|
10
testing/btest/Files/zeek-aux-Logs/onecolumn.log
Normal file
10
testing/btest/Files/zeek-aux-Logs/onecolumn.log
Normal file
|
@ -0,0 +1,10 @@
|
|||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path onecolumn
|
||||
#open 2014-04-01-23-15-59
|
||||
#fields id.orig_h
|
||||
#types addr
|
||||
79.26.245.236
|
||||
#close 2014-04-01-23-15-59
|
15
testing/btest/Files/zeek-aux-Logs/test.log
Normal file
15
testing/btest/Files/zeek-aux-Logs/test.log
Normal file
|
@ -0,0 +1,15 @@
|
|||
#separator \x09
|
||||
#set_separator ,
|
||||
#empty_field (empty)
|
||||
#unset_field -
|
||||
#path test
|
||||
#open 2014-04-01-23-15-51
|
||||
#fields ts uid id.orig_h id.orig_p id.resp_h
|
||||
#types time string addr port addr
|
||||
1329327783.316897 CjhGID4nQcgTWjvg4c 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49186 2001:470:4867:99::21
|
||||
1329327786.524332 CCvvfg3TEfuqmmG4bh 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49187 2001:470:4867:99::21
|
||||
1329327787.289095 CsRx2w45OKnoww6xl4 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49188 2001:470:4867:99::21
|
||||
1329327795.571921 CRJuHdVW0XPVINV8a 2001:470:4867:99::21 55785 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
1329327777.822004 CXWv6p3arKYeMETxOg 2001:470:1f11:81f:c999:d94:aa7c:2e3e 49185 2001:470:4867:99::21
|
||||
1329327800.017649 CPbrpk1qSsw6ESzHV4 2001:470:4867:99::21 55647 2001:470:1f11:81f:c999:d94:aa7c:2e3e
|
||||
#close 2014-04-01-23-15-51
|
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue