zeek/testing/btest/language/init-in-anon-function.zeek
Robin Sommer 789cb376fd GH-239: Rename bro to zeek, bro-config to zeek-config, and bro-path-dev to zeek-path-dev.
This also installs symlinks from "zeek" and "bro-config" to a wrapper
script that prints a deprecation warning.

The btests pass, but this is still WIP. broctl renaming is still
missing.

#239
2019-05-01 21:43:45 +00:00

16 lines
518 B
Text

# @TEST-EXEC: zeek -r ${TRACES}/wikipedia.trace %INPUT >out
# @TEST-EXEC: btest-diff http.log
module Foo;
event zeek_init() {
Log::remove_default_filter(HTTP::LOG);
local filter: Log::Filter = [$name = "http",
$pred = function(rec: HTTP::Info): bool {
rec$id$orig_h = remask_addr(rec$id$orig_h, 0.0.0.0, 112);
return T;
}];
Log::add_filter(HTTP::LOG, filter);
}