Seth Hall
04e2773d30
Fixed some bugs with capturing data in the base DNS script.
2011-12-08 13:06:45 -05:00
Jon Siwek
5126b65493
Add reporter bif/framework documentation.
2011-12-07 16:54:40 -06:00
Bernhard Amann
89a29c3d7d
Merge remote-tracking branch 'origin/master' into topic/bernhard/input
2011-12-07 13:13:43 -08:00
Bernhard Amann
707926aaa4
Software framework stores ports for server software.
2011-12-07 12:12:46 -08:00
Jon Siwek
506a42638a
Omit loading local-<node>.bro scripts from base cluster framework.
...
The loading of these is better handled by BroControl and it seems
odd to load them from a base/ script anyway since they'll contain
site/policy specific code.
Addresses #663
2011-12-05 13:02:39 -06:00
Bernhard Amann
949ec6897a
Merge remote-tracking branch 'origin/master' into topic/bernhard/localnet
2011-12-03 20:15:05 -08:00
Robin Sommer
df3ae4b30d
Merge remote-tracking branch 'origin/topic/jsiwek/remote-log-peer'
...
* origin/topic/jsiwek/remote-log-peer:
Add a remote_log_peer event which contains an event_peer record param.
Closes #493 .
2011-12-01 16:02:11 -08:00
Jon Siwek
0c8b5a712d
Add a remote_log_peer event which contains an event_peer record param.
...
Addresses #493 .
2011-12-01 14:07:08 -06:00
Seth Hall
70004cb04d
Small updates to address the "globals" ticket.
...
Fixes #633
2011-11-30 11:35:53 -05:00
Seth Hall
bb47289bfa
Some updates to the base DNS script.
...
- Answers and TTLs are now vectors.
- The warning that was being generated (dns_reply_seen_after_done)
from transaction ID reuse is fixed.
- Updated the single failing btest baseline.
2011-11-30 10:19:41 -05:00
Bernhard Amann
a68e6b9fa4
allow sets to be read from files, convenience function for reading a file once,
...
bug in destructor that could lead to a segfault.
2011-11-29 15:05:09 -08:00
Bernhard Amann
2a6387129c
documentation
2011-11-29 11:25:11 -08:00
Bernhard Amann
4975584e01
change Log enum to Input enum.
2011-11-28 13:45:00 -08:00
Bernhard Amann
3c40f00a53
make filters pointers (for inheritance)
2011-11-22 16:09:13 -08:00
Bernhard Amann
53af0544cc
re-enable table events
2011-11-21 19:03:35 -08:00
Bernhard Amann
18591b53d4
rename filter to tablefilter in preparation of event filters...
2011-11-21 15:20:52 -08:00
Matthias Vallentin
0325b5ea32
to_port() now parses a string instead of a count.
...
Addresses #684 .
2011-11-20 21:41:41 -08:00
Bernhard Amann
b3f01915fb
compiles with basic new filter framework - but crashes on use.
2011-11-20 12:07:50 -08:00
Bernhard Amann
e2c521fc4e
start reworking input framework...
...
does not compile at the moment, but there are a few uncommitted changes that will be reverted in the next commit.
2011-11-18 10:49:20 -08:00
Bernhard Amann
4dd95fcf3c
support for uninitialized fields & empty sets and tables.
...
The only snag is... with the default output format of the log-file writer, the input reader cannot tell if a table or set is empty or uninitialized (both cases use the same character by default). In this case, by default it is assumed that the field/vector is uninitalized.
2011-11-16 23:51:51 -08:00
Bernhard Amann
4fef1e3f8c
set & entry separator configuration (with the restriction that they have to be exactly one character long)
2011-11-16 22:47:28 -08:00
Robin Sommer
c35094ea0b
Update missing in last commit to this branch.
2011-11-15 16:42:23 -08:00
Bernhard Amann
b62e6899ad
Merge remote-tracking branch 'origin/master' into topic/bernhard/input
2011-11-15 11:00:24 -08:00
Robin Sommer
2dc04b2ce5
Merge remote-tracking branch 'origin/master' into topic/robin/pp-alarms
2011-11-15 08:36:44 -08:00
Bernhard Amann
cde8153c18
switch to set if record or simple value is desired.
2011-11-15 08:36:03 -08:00
Robin Sommer
fa76330afb
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
Binary packaging script tweaks.
More default "weird" tuning for the "SYN_with_data" notice.
Tiny bugfix for http file extraction along with test.
2011-11-15 07:53:36 -08:00
Seth Hall
4942767c4d
More default "weird" tuning for the "SYN_with_data" notice.
...
- I think the default tuning should be that anything not requiring
a session to be established should use ACTION_LOG_PER_ORIG.
- We need to get some tie-in with the metrics framework in place
so that we can find when lots of these values are being suppressed.
2011-11-14 16:12:38 -05:00
Seth Hall
d14349a6f8
Merge remote-tracking branch 'origin/master' into fastpath
2011-11-14 16:06:44 -05:00
Seth Hall
b12d2c768e
Tiny bugfix for http file extraction along with test.
2011-11-14 15:24:15 -05:00
Bernhard Amann
1d39eaf32d
small fixes, less leakiness
2011-11-04 15:03:40 -07:00
Bernhard Amann
2aa0f6da57
beautify script calls, track filters
2011-11-04 14:33:34 -07:00
Bernhard Amann
72736510de
Merge remote-tracking branch 'origin/master' into input
2011-11-04 14:12:59 -07:00
Bernhard Amann
2e3874331d
support for filters and little event fix
2011-11-04 12:41:10 -07:00
Robin Sommer
e0692b898e
Merge branch 'master' into topic/robin/pp-alarms
2011-11-03 15:30:41 -07:00
Robin Sommer
41a443677b
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
No longer write to the PacketFilter::LOG stream if not reading traffic.
2011-11-03 15:27:23 -07:00
Robin Sommer
c4d6f814ff
Tuning the pretty-printed alarms output.
...
- Now including the included time range into the subject.
- With some notices, it got confused who's the orginator.
2011-11-02 18:09:09 -07:00
Bernhard Amann
86730c13dd
more complex types...
2011-11-02 15:36:35 -07:00
Bernhard Amann
b245d4168a
yay, basic table assignment.
2011-11-02 15:36:35 -07:00
Bernhard Amann
5b0c307f87
very basic input to event working...
2011-11-02 15:36:34 -07:00
Bernhard Amann
3654060246
compiles. sill doesn't do much.
2011-11-02 15:36:34 -07:00
Bernhard Amann
9c8b0dec3b
event from c++ to script works (at last...)
2011-11-02 15:36:33 -07:00
Bernhard Amann
0eafeb0369
works (thanks to robin)
2011-11-02 15:36:33 -07:00
Seth Hall
507b51c957
No longer write to the PacketFilter::LOG stream if not reading traffic.
2011-11-02 15:09:57 -04:00
Seth Hall
ae3ae9a75b
Awful fix for SSH login detection.
...
- We need a counted measure of payload bytes (not ack tracking and
not with the IP header which is what we have now).
2011-10-27 09:41:34 -04:00
Robin Sommer
f3ed235ba7
Tuning the format of the pretty-printed alarm summaries.
...
Turns out the old format doesn't work well with the new scripts.
2011-10-26 21:12:16 -07:00
Robin Sommer
5b79d2b15f
Baseline updates.
...
Also a small tweak to the genDocSourcesList.sh as I was seein
non-consistent output order.
2011-10-26 15:27:03 -07:00
Robin Sommer
ec2a8d7904
Merge remote-tracking branch 'origin/topic/robin/pp-alarms'
...
* origin/topic/robin/pp-alarms:
Removing debugging code.
Now actually pretty-printing the notices.
Small fixes, and new option to specify a different dest address.
A new notice script that pretty-prints alarms in the summary email.
Adding a dummy log writer WRITER_NONE that just discards everything.
2011-10-26 14:44:46 -07:00
Robin Sommer
314e9c41f9
Removing debugging code.
2011-10-26 14:39:07 -07:00
Robin Sommer
eb6313adcb
Now actually pretty-printing the notices.
...
Output is similar to Bro 1.x.
2011-10-26 13:42:42 -07:00
Robin Sommer
39ed489028
Small fixes, and new option to specify a different dest address.
2011-10-26 11:12:50 -07:00