mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

- The bit-length is adjustable via redef'ing bits_per_uid. - Prefix 'C' is used for connection UIDS (including IP tunnels) and 'F' for files.
10 lines
407 B
Text
10 lines
407 B
Text
#separator \x09
|
|
#set_separator ,
|
|
#empty_field (empty)
|
|
#unset_field -
|
|
#path dhcp
|
|
#open 2013-08-26-19-04-04
|
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p mac assigned_ip lease_time trans_id
|
|
#types time string addr port addr port string addr interval count
|
|
1374432420.191205 CXWv6p3arKYeMETxOg 128.2.6.122 68 128.2.6.152 67 90:b1:1c:99:49:29 128.2.6.122 0.000000 2754407505
|
|
#close 2013-08-26-19-04-04
|