zeek/testing/btest/Baseline/scripts.base.frameworks.logging.remove/ssh.log
Robin Sommer 1fd0d7a607 Changing the start/end markers in logs to open/close now reflecting
wall clock.

Triggers lots of (simple) baseline updates.
2012-07-27 12:15:21 -07:00

12 lines
402 B
Text

#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path ssh
#open 2012-07-20-01-49-21
#fields t id.orig_h id.orig_p id.resp_h id.resp_p status country
#types time addr port addr port string string
1342748961.521536 1.2.3.4 1234 2.3.4.5 80 failure US
1342748961.521536 1.2.3.4 1234 2.3.4.5 80 failure UK
1342748961.521536 1.2.3.4 1234 2.3.4.5 80 failure BR
#close 2012-07-20-01-49-21