mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
![]() The changes are mostly quite minor. The main change reasons are: * analyzers that were confirmed, and later removed now show up in the conn.log. * a couple of removed lines in analyzer.log, because non-confirmed analyzers get removed more quickly. * in some cases there are additional lines in analyzer.log. These are cases in which an analyzer gets removed due to a violation and then re-attached because of a later signature match, which replays the violating content. In all examples that I have so far, this is caused by both sides of a connection speaking a differing protocol. There probably should be a better way to handle this - but it works. * new column for failed analyzers in conn.log |
||
---|---|---|
.. | ||
benchmark/broker | ||
btest | ||
builtin-plugins | ||
coverage | ||
external | ||
scripts | ||
.gitignore | ||
CMakeLists.txt | ||
Makefile | ||
README |
This directory contains suites for testing for Zeek's correct operation: btest/ An ever-growing set of small unit tests testing Zeek's functionality. external/ A framework for downloading additional test sets that run more complex Zeek configuration on larger traces files. Due to their size, these are not included directly. See the README for more information. scripts/ Helpers scripts used by some tests.