mirror of
https://github.com/zeek/zeek.git
synced 2025-10-11 19:18:19 +00:00
81 lines
7.2 KiB
Text
81 lines
7.2 KiB
Text
# Extent Types ...
|
|
<ExtentType name="DataSeries: ExtentIndex">
|
|
<field type="int64" name="offset" />
|
|
<field type="variable32" name="extenttype" />
|
|
</ExtentType>
|
|
|
|
<ExtentType name="DataSeries: XmlType">
|
|
<field type="variable32" name="xmltype" />
|
|
</ExtentType>
|
|
|
|
<ExtentType name="http" version="1.0" namespace="bro.org">
|
|
<field type="double" name="ts" pack_relative="ts" pack_scale="1e-6" print_format="%.6f" pack_scale_warn="no"/>
|
|
<field type="variable32" name="uid" pack_unique="yes"/>
|
|
<field type="variable32" name="id.orig_h" pack_unique="yes"/>
|
|
<field type="int64" name="id.orig_p" />
|
|
<field type="variable32" name="id.resp_h" pack_unique="yes"/>
|
|
<field type="int64" name="id.resp_p" />
|
|
<field type="int64" name="trans_depth" />
|
|
<field type="variable32" name="method" pack_unique="yes"/>
|
|
<field type="variable32" name="host" pack_unique="yes"/>
|
|
<field type="variable32" name="uri" pack_unique="yes"/>
|
|
<field type="variable32" name="referrer" pack_unique="yes"/>
|
|
<field type="variable32" name="user_agent" pack_unique="yes"/>
|
|
<field type="int64" name="request_body_len" />
|
|
<field type="int64" name="response_body_len" />
|
|
<field type="int64" name="status_code" />
|
|
<field type="variable32" name="status_msg" pack_unique="yes"/>
|
|
<field type="int64" name="info_code" />
|
|
<field type="variable32" name="info_msg" pack_unique="yes"/>
|
|
<field type="variable32" name="filename" pack_unique="yes"/>
|
|
<field type="variable32" name="tags" pack_unique="yes"/>
|
|
<field type="variable32" name="username" pack_unique="yes"/>
|
|
<field type="variable32" name="password" pack_unique="yes"/>
|
|
<field type="variable32" name="proxied" pack_unique="yes"/>
|
|
<field type="variable32" name="mime_type" pack_unique="yes"/>
|
|
<field type="variable32" name="md5" pack_unique="yes"/>
|
|
<field type="variable32" name="extraction_file" pack_unique="yes"/>
|
|
</ExtentType>
|
|
<!-- ts : time -->
|
|
<!-- uid : string -->
|
|
<!-- id.orig_h : addr -->
|
|
<!-- id.orig_p : port -->
|
|
<!-- id.resp_h : addr -->
|
|
<!-- id.resp_p : port -->
|
|
<!-- trans_depth : count -->
|
|
<!-- method : string -->
|
|
<!-- host : string -->
|
|
<!-- uri : string -->
|
|
<!-- referrer : string -->
|
|
<!-- user_agent : string -->
|
|
<!-- request_body_len : count -->
|
|
<!-- response_body_len : count -->
|
|
<!-- status_code : count -->
|
|
<!-- status_msg : string -->
|
|
<!-- info_code : count -->
|
|
<!-- info_msg : string -->
|
|
<!-- filename : string -->
|
|
<!-- tags : table[enum] -->
|
|
<!-- username : string -->
|
|
<!-- password : string -->
|
|
<!-- proxied : table[string] -->
|
|
<!-- mime_type : string -->
|
|
<!-- md5 : string -->
|
|
<!-- extraction_file : file -->
|
|
|
|
# Extent, type='http'
|
|
ts uid id.orig_h id.orig_p id.resp_h id.resp_p trans_depth method host uri referrer user_agent request_body_len response_body_len status_code status_msg info_code info_msg filename tags username password proxied mime_type md5 extraction_file
|
|
1300475168.784020 j4u32Pc5bif 141.142.220.118 48649 208.80.152.118 80 1 GET bits.wikimedia.org /skins-1.5/monobook/main.css http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.916018 VW0XPVINV8a 141.142.220.118 49997 208.80.152.3 80 1 GET upload.wikimedia.org /wikipedia/commons/6/63/Wikipedia-logo.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.916183 3PKsZ2Uye21 141.142.220.118 49996 208.80.152.3 80 1 GET upload.wikimedia.org /wikipedia/commons/thumb/b/bb/Wikipedia_wordmark.svg/174px-Wikipedia_wordmark.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.918358 GSxOnSLghOa 141.142.220.118 49998 208.80.152.3 80 1 GET upload.wikimedia.org /wikipedia/commons/b/bd/Bookshelf-40x201_6.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.952307 Tw8jXtpTGu6 141.142.220.118 50000 208.80.152.3 80 1 GET upload.wikimedia.org /wikipedia/commons/thumb/8/8a/Wikinews-logo.png/35px-Wikinews-logo.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.952296 P654jzLoe3a 141.142.220.118 49999 208.80.152.3 80 1 GET upload.wikimedia.org /wikipedia/commons/4/4a/Wiktionary-logo-en-35px.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.954820 0Q4FH8sESw5 141.142.220.118 50001 208.80.152.3 80 1 GET upload.wikimedia.org /wikipedia/commons/thumb/f/fa/Wikiquote-logo.svg/35px-Wikiquote-logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.962687 i2rO3KD1Syg 141.142.220.118 35642 208.80.152.2 80 1 GET meta.wikimedia.org /images/wikimedia-button.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.975934 VW0XPVINV8a 141.142.220.118 49997 208.80.152.3 80 2 GET upload.wikimedia.org /wikipedia/commons/thumb/f/fa/Wikibooks-logo.svg/35px-Wikibooks-logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.976436 3PKsZ2Uye21 141.142.220.118 49996 208.80.152.3 80 2 GET upload.wikimedia.org /wikipedia/commons/thumb/d/df/Wikispecies-logo.svg/35px-Wikispecies-logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475168.979264 GSxOnSLghOa 141.142.220.118 49998 208.80.152.3 80 2 GET upload.wikimedia.org /wikipedia/commons/thumb/4/4c/Wikisource-logo.svg/35px-Wikisource-logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475169.014619 Tw8jXtpTGu6 141.142.220.118 50000 208.80.152.3 80 2 GET upload.wikimedia.org /wikipedia/commons/thumb/4/4a/Commons-logo.svg/35px-Commons-logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475169.014593 P654jzLoe3a 141.142.220.118 49999 208.80.152.3 80 2 GET upload.wikimedia.org /wikipedia/commons/thumb/9/91/Wikiversity-logo.svg/35px-Wikiversity-logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|
|
1300475169.014927 0Q4FH8sESw5 141.142.220.118 50001 208.80.152.3 80 2 GET upload.wikimedia.org /wikipedia/commons/thumb/7/75/Wikimedia_Community_Logo.svg/35px-Wikimedia_Community_Logo.svg.png http://www.wikipedia.org/ Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.15) Gecko/20110303 Ubuntu/10.04 (lucid) Firefox/3.6.15 0 0 304 Not Modified 0
|