mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 10:08:20 +00:00

Part of this involves making the file-analysis tests independent of specific hash values. I've done that only partially though.
12 lines
697 B
Text
12 lines
697 B
Text
#separator \x09
|
|
#set_separator ,
|
|
#empty_field (empty)
|
|
#unset_field -
|
|
#path smtp_entities
|
|
#open 2013-05-17-23-19-41
|
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p trans_depth filename content_len mime_type md5 extraction_file excerpt
|
|
#types time string addr port addr port count string count string string string string
|
|
1254722770.692743 arKYeMETxOg 10.10.1.4 1470 74.53.140.153 25 1 - 79 text/plain - smtp-entity-mR3f2AAKo11-0.dat (empty)
|
|
1254722770.692743 arKYeMETxOg 10.10.1.4 1470 74.53.140.153 25 1 - 1918 text/html - - (empty)
|
|
1254722770.692804 arKYeMETxOg 10.10.1.4 1470 74.53.140.153 25 1 NEWS.txt 10823 text/plain - smtp-entity-ZNp0KBSLByc-1.dat (empty)
|
|
#close 2013-05-17-23-19-41
|