zeek/testing/btest/Baseline/scripts.base.protocols.snmp.v2/out1
Jon Siwek a0c06a957b Add SNMP datagram parsing support.
This supports parsing of SNMPv1 (RFC 1157), SNMPv2 (RFC 1901/3416), and
SNMPv2 (RFC 3412).  An event is raised for each SNMP PDU type, though
there's not currently any event handlers for them and not a default
snmp.log either.  However, simple presence of SNMP is currently visible
now in conn.log service field and known_services.log.
2014-02-18 14:41:32 -06:00

18 lines
506 B
Text

snmp_get_request
[orig_h=10.10.1.159, orig_p=51217/udp, resp_h=10.10.3.109, resp_p=161/udp]
is_orig: T
[community=public]
request_id: 895734538
error_stat: 0
error_idx: 0
oid: 1.3.6.1.2.1.2.2.1.17.1
value (tag=0x05): <unspecified>
snmp_response
[orig_h=10.10.1.159, orig_p=51217/udp, resp_h=10.10.3.109, resp_p=161/udp]
is_orig: F
[community=public]
request_id: 895734538
error_stat: 0
error_idx: 0
oid: 1.3.6.1.2.1.2.2.1.17.1
value (tag=0x41): 854387