mirror of
https://github.com/zeek/zeek.git
synced 2025-10-05 08:08:19 +00:00

This introduces ian options, DPD::track_removed_services_in_connection. It adds failed services to the services column, prefixed with a "-". Alternatively, this commit also adds policy/protocols/conn/failed-services.zeek, which provides the same information in a new column in conn.log.
7 lines
256 B
Text
7 lines
256 B
Text
# @TEST-DOC: Check if DPD options on violations work.
|
|
# @TEST-EXEC: zeek -r $TRACES/ftp/ftp-invalid-reply-code.pcap %INPUT
|
|
# @TEST-EXEC: btest-diff conn.log
|
|
|
|
@load policy/protocols/conn/failed-services
|
|
|
|
redef DPD::track_removed_services_in_connection = T;
|