mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

The changes are mostly quite minor. The main change reasons are: * analyzers that were confirmed, and later removed now show up in the conn.log. * a couple of removed lines in analyzer.log, because non-confirmed analyzers get removed more quickly. * in some cases there are additional lines in analyzer.log. These are cases in which an analyzer gets removed due to a violation and then re-attached because of a later signature match, which replays the violating content. In all examples that I have so far, this is caused by both sides of a connection speaking a differing protocol. There probably should be a better way to handle this - but it works. * new column for failed analyzers in conn.log
1 line
41 B
Text
1 line
41 B
Text
6a1cb339d394fe8d73c0f46e79bd13fbee507313
|