mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

This is similar to what the external corelight/zeek-smb-clear-state script does, but leverages the smb2_discarded_messages_state() event instead of regularly checking on the state of SMB connections. The pcap was created using the dperson/samba container image and mounting a share with Linux's CIFS filesystem, then copying the content of a directory with 100 files. The test uses a BPF filter to imitate mostly "half-duplex" traffic.
25 lines
1.2 KiB
Text
25 lines
1.2 KiB
Text
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, read, 15
|
|
smb2_discarded_messages_state after, read, 0
|
|
smb2_discarded_messages_state before, tree, 5
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, read, 15
|
|
smb2_discarded_messages_state after, read, 0
|
|
smb2_discarded_messages_state before, tree, 5
|
|
smb2_discarded_messages_state after, tree, 0
|
|
smb2_discarded_messages_state before, tree, 20
|
|
smb2_discarded_messages_state after, tree, 0
|