mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Update btest baselines for analyzer history
This commit is contained in:
parent
29bc84e1d6
commit
f18c28cfe5
4 changed files with 15 additions and 12 deletions
|
@ -1,2 +1,2 @@
|
||||||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||||
ETHERNET, 35020, 02070400222d81db1004
|
ETHERNET, 35020, 02070400222d81db1004, [ETHERNET]
|
||||||
|
|
|
@ -5,9 +5,9 @@
|
||||||
#unset_field -
|
#unset_field -
|
||||||
#path unknown_protocols
|
#path unknown_protocols
|
||||||
#open XXXX-XX-XX-XX-XX-XX
|
#open XXXX-XX-XX-XX-XX-XX
|
||||||
#fields ts analyzer protocol_id first_bytes
|
#fields ts analyzer protocol_id first_bytes analyzer_history
|
||||||
#types time string string string
|
#types time string string string vector[string]
|
||||||
XXXXXXXXXX.XXXXXX IP 0xfd 1b794b175fac06aba658
|
XXXXXXXXXX.XXXXXX IP 0xfd 1b794b175fac06aba658 ETHERNET,VNTAG,VLAN,IP
|
||||||
XXXXXXXXXX.XXXXXX IP 0xfd 9d6c1f9e20274bb66385
|
XXXXXXXXXX.XXXXXX IP 0xfd 9d6c1f9e20274bb66385 ETHERNET,VNTAG,VLAN,IP
|
||||||
XXXXXXXXXX.XXXXXX IP 0xfd 06ffb64ded001f65f818
|
XXXXXXXXXX.XXXXXX IP 0xfd 06ffb64ded001f65f818 ETHERNET,VNTAG,VLAN,IP
|
||||||
#close XXXX-XX-XX-XX-XX-XX
|
#close XXXX-XX-XX-XX-XX-XX
|
||||||
|
|
|
@ -5,7 +5,7 @@
|
||||||
#unset_field -
|
#unset_field -
|
||||||
#path unknown_protocols
|
#path unknown_protocols
|
||||||
#open XXXX-XX-XX-XX-XX-XX
|
#open XXXX-XX-XX-XX-XX-XX
|
||||||
#fields ts analyzer protocol_id first_bytes
|
#fields ts analyzer protocol_id first_bytes analyzer_history
|
||||||
#types time string string string
|
#types time string string string vector[string]
|
||||||
XXXXXXXXXX.XXXXXX ETHERNET 0x88b5 4920616d20656e636170
|
XXXXXXXXXX.XXXXXX ETHERNET 0x88b5 4920616d20656e636170 ETHERNET
|
||||||
#close XXXX-XX-XX-XX-XX-XX
|
#close XXXX-XX-XX-XX-XX-XX
|
||||||
|
|
|
@ -1,6 +1,9 @@
|
||||||
# @TEST-EXEC: zeek -b -r $TRACES/lldp.pcap %INPUT >out
|
# @TEST-EXEC: zeek -b -r $TRACES/lldp.pcap %INPUT >out
|
||||||
# @TEST-EXEC: btest-diff out
|
# @TEST-EXEC: btest-diff out
|
||||||
|
|
||||||
event unknown_protocol(analyzer_name: string, protocol: count, first_bytes: string)
|
event unknown_protocol(analyzer_name: string, protocol: count, first_bytes: string,
|
||||||
{ print analyzer_name, protocol, bytestring_to_hexstr(first_bytes); }
|
analyzer_history: string_vec)
|
||||||
|
{
|
||||||
|
print analyzer_name, protocol, bytestring_to_hexstr(first_bytes),
|
||||||
|
analyzer_history;
|
||||||
|
}
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue