zeek/testing/btest/language/init-in-anon-function.zeek
Jon Siwek 7967a5b0aa General btest cleanup
- Use `-b` most everywhere, it will save time.

- Start some intel tests upon the input file being fully read instead of
  at an arbitrary time.

- Improve termination condition for some sumstats/cluster tests.

- Filter uninteresting output from some supervisor tests.

- Test for `notice_policy.log` is no longer needed.
2020-08-11 11:26:22 -07:00

18 lines
548 B
Text

# @TEST-EXEC: zeek -b -r ${TRACES}/wikipedia.trace %INPUT >out
# @TEST-EXEC: btest-diff http.log
@load base/protocols/http
module Foo;
event zeek_init() {
Log::remove_default_filter(HTTP::LOG);
local filter: Log::Filter = [$name = "http",
$pred = function(rec: HTTP::Info): bool {
rec$id$orig_h = remask_addr(rec$id$orig_h, 0.0.0.0, 112);
return T;
}];
Log::add_filter(HTTP::LOG, filter);
}