mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 01:58:20 +00:00
New script misc/dump-events.bro, along with core support, that dumps events Bro is raising
in an easily readable form. This is for debugging purposes, obviously. Example, including only SMTP events: > bro -r smtp.trace misc/dump-events.bro DumpEvents::include=/smtp/ [...] 1254722768.219663 smtp_reply [0] c: connection = [id=[orig_h=10.10.1.4, orig_p=1470/tcp, resp_h=74.53.140.153, [...] [1] is_orig: bool = F [2] code: count = 220 [3] cmd: string = > [4] msg: string = xc90.websitewelcome.com ESMTP Exim 4.69 #1 Mon, 05 Oct 2009 01:05:54 -0500 [5] cont_resp: bool = T 1254722768.219663 smtp_reply [0] c: connection = [id=[orig_h=10.10.1.4, orig_p=1470/tcp, resp_h=74.53.140.153, [...] [1] is_orig: bool = F [2] code: count = 220 [3] cmd: string = > [4] msg: string = We do not authorize the use of this system to transport unsolicited, [5] cont_resp: bool = T [...]
This commit is contained in:
parent
08c7dd3d71
commit
de9f03b0bf
7 changed files with 126 additions and 0 deletions
|
@ -235,6 +235,8 @@ RecordType* script_id;
|
|||
TableType* id_table;
|
||||
RecordType* record_field;
|
||||
TableType* record_field_table;
|
||||
RecordType* call_argument;
|
||||
VectorType* call_argument_vector;
|
||||
|
||||
StringVal* cmd_line_bpf_filter;
|
||||
|
||||
|
@ -528,4 +530,6 @@ void init_net_var()
|
|||
id_table = internal_type("id_table")->AsTableType();
|
||||
record_field = internal_type("record_field")->AsRecordType();
|
||||
record_field_table = internal_type("record_field_table")->AsTableType();
|
||||
call_argument_vector = internal_type("call_argument_vector")->AsVectorType();
|
||||
call_argument = internal_type("call_argument")->AsRecordType();
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue