zeek/testing/btest/Baseline/scripts.base.protocols.socks.trace1/socks.log
Robin Sommer 1fd0d7a607 Changing the start/end markers in logs to open/close now reflecting
wall clock.

Triggers lots of (simple) baseline updates.
2012-07-27 12:15:21 -07:00

10 lines
488 B
Text

#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path socks
#open 2012-06-20-17-23-38
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p version user status request.host request.name request_p bound.host bound.name bound_p
#types time string addr port addr port count string string addr string port addr string port
1340213015.276495 UWkUyAuUGXf 10.0.0.55 53994 60.190.189.214 8124 5 - succeeded - www.osnews.com 80 192.168.0.31 - 2688
#close 2012-06-20-17-28-10