mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

The changes are mostly quite minor. The main change reasons are: * analyzers that were confirmed, and later removed now show up in the conn.log. * a couple of removed lines in analyzer.log, because non-confirmed analyzers get removed more quickly. * in some cases there are additional lines in analyzer.log. These are cases in which an analyzer gets removed due to a violation and then re-attached because of a later signature match, which replays the violating content. In all examples that I have so far, this is caused by both sides of a connection speaking a differing protocol. There probably should be a better way to handle this - but it works. * new column for failed analyzers in conn.log
1 line
41 B
Text
1 line
41 B
Text
ae8e70135812845ef68ac0f8ce2426ad2ff82469
|