mirror of
https://github.com/zeek/zeek.git
synced 2025-10-03 15:18:20 +00:00

Do a better job of parsing layer 2 and keeping track of layer 3 proto. Add support for raw packet event, including Layer2 headers.
9 lines
213 B
Text
9 lines
213 B
Text
# @TEST-EXEC: bro -b -r $TRACES/raw_packets.trace %INPUT >output
|
|
# @TEST-EXEC: bro -b -r $TRACES/icmp_dot1q.trace %INPUT >>output
|
|
# @TEST-EXEC: btest-diff output
|
|
|
|
event raw_packet(p: raw_pkt_hdr)
|
|
{
|
|
print p;
|
|
}
|
|
|