zeek/scripts/base/protocols/smtp/file-analysis.bro
Jon Siwek 661677d452 FileAnalysis: separating IRC/FTP data analyzers.
It simplifies the file handle string callbacks.
2013-03-20 11:12:06 -05:00

18 lines
407 B
Text

@load ./main
@load ./entities
@load base/utils/conn-ids
@load base/frameworks/file-analysis/main
module SMTP;
function get_file_handle(c: connection, is_orig: bool): string
{
if ( ! c?$smtp ) return "";
return fmt("%s %s %s %s", ANALYZER_SMTP, c$start_time, c$smtp$trans_depth,
c$smtp_state$mime_level);
}
redef FileAnalysis::handle_callbacks += {
[ANALYZER_SMTP] = get_file_handle,
};