zeek/testing/btest/Baseline/policy.frameworks.logging.ascii-empty/ssh.log
Gilbert Clark gc355804@ohio.edu 3b411b69f3 Updated header format (see #558)
2011-08-30 11:20:28 -07:00

9 lines
479 B
Text

PREFIX<>separator \x7c
PREFIX<>fields|t|id.orig_h|id.orig_p|id.resp_h|id.resp_p|status|country|b
PREFIX<>types|time|addr|port|addr|port|string|string|bool
PREFIX<>path|ssh
1314727948.493595|1.2.3.4|1234|2.3.4.5|80|success|unknown|NOT-SET
1314727948.493595|1.2.3.4|1234|2.3.4.5|80|NOT-SET|US|NOT-SET
1314727948.493595|1.2.3.4|1234|2.3.4.5|80|failure|UK|NOT-SET
1314727948.493595|1.2.3.4|1234|2.3.4.5|80|NOT-SET|BR|NOT-SET
1314727948.493595|1.2.3.4|1234|2.3.4.5|80|failure|EMPTY|T