Some small fixes to further reduce SOCKS false positive logs.

This commit is contained in:
Seth Hall 2012-07-11 16:53:46 -04:00
parent e3f6a467a4
commit a44612788e
2 changed files with 12 additions and 2 deletions

View file

@ -83,5 +83,8 @@ event socks_reply(c: connection, version: count, reply: count, sa: SOCKS::Addres
event socks_reply(c: connection, version: count, reply: count, sa: SOCKS::Address, p: port) &priority=-5
{
Log::write(SOCKS::LOG, c$socks);
# This will handle the case where the analyzer failed in some way and was removed. We probably
# don't want to log these connections.
if ( "SOCKS" in c$service )
Log::write(SOCKS::LOG, c$socks);
}