zeek/testing/btest/Baseline/scripts.base.frameworks.logging.ascii-escape/ssh.log
Robin Sommer 1fd0d7a607 Changing the start/end markers in logs to open/close now reflecting
wall clock.

Triggers lots of (simple) baseline updates.
2012-07-27 12:15:21 -07:00

14 lines
573 B
Text

#separator ||
#set_separator||,
#empty_field||(empty)
#unset_field||-
#path||ssh
#open||2012-07-27-19-14-35
#fields||t||id.orig_h||id.orig_p||id.resp_h||id.resp_p||status||country
#types||time||addr||port||addr||port||string||string
1343416475.837726||1.2.3.4||1234||2.3.4.5||80||success||unknown
1343416475.837726||1.2.3.4||1234||2.3.4.5||80||failure||US
1343416475.837726||1.2.3.4||1234||2.3.4.5||80||fa\x7c\x7cure||UK
1343416475.837726||1.2.3.4||1234||2.3.4.5||80||su\x7c\x7cess||BR
1343416475.837726||1.2.3.4||1234||2.3.4.5||80||failure||MX
#close||2012-07-27-19-14-35