zeek/testing/btest/Baseline/core.udp-padding/syslog.log
Johanna Amann a391367c36 Do not forward more than the remaining data to downstream UDP analyzer
This fixes a bug introduced in 2b9de839b0
/ GH-3080, which causes UDP padding to be sent to UDP based analyzers.

Fixes GH-3205.
2023-07-27 13:35:41 +01:00

15 lines
937 B
Text

### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path syslog
#open XXXX-XX-XX-XX-XX-XX
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto facility severity message
#types time string addr port addr port enum string string string
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 169.229.152.216 39887 192.150.187.42 514 udp UNSPECIFIED UNSPECIFIED X
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 169.229.152.216 39887 192.150.187.42 514 udp UNSPECIFIED UNSPECIFIED X
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 169.229.152.216 39887 192.150.187.42 514 udp UNSPECIFIED UNSPECIFIED X
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 169.229.152.216 39887 192.150.187.42 514 udp UNSPECIFIED UNSPECIFIED X
XXXXXXXXXX.XXXXXX CHhAvVGS1DHFjwGM9 169.229.152.216 39887 192.150.187.42 514 udp UNSPECIFIED UNSPECIFIED X
#close XXXX-XX-XX-XX-XX-XX