zeek/testing/btest/Baseline/scripts.base.frameworks.logging.empty-event/ssh.log
Robin Sommer 3220bbce55 Merge remote branch 'origin/topic/jsiwek/log-escaping'
* origin/topic/jsiwek/log-escaping:
  Add missing ascii writer options to log header.
  Escape the ASCII log's set separator (addresses #712)
  Rewrite ODesc character escaping functionality. (addresses #681)

Closes #712.
2011-12-19 06:37:54 -08:00

12 lines
463 B
Text

#separator \x09
#set_separator \x2c
#empty_field \x2d
#unset_field \x2d
#path ssh
#fields t id.orig_h id.orig_p id.resp_h id.resp_p status country
#types time addr port addr port string string
1323275824.696040 1.2.3.4 1234 2.3.4.5 80 success unknown
1323275824.696040 1.2.3.4 1234 2.3.4.5 80 failure US
1323275824.696040 1.2.3.4 1234 2.3.4.5 80 failure UK
1323275824.696040 1.2.3.4 1234 2.3.4.5 80 success BR
1323275824.696040 1.2.3.4 1234 2.3.4.5 80 failure MX