mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00
145 lines
3.3 KiB
Text
145 lines
3.3 KiB
Text
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
sdfkh:KH;fdkncv;ISEUp34:Fkdj;YVpIODhfDF
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
DSF"DFKJ"SDFKLh304yrsdkfj@#(*U$34jfDJup3UF
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
q3r3057fdf
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
sdfs\d
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
dfsdf
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
sdf
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
3rw43wRRERLlL#RWERERERE.
|
|
[source=tail -f ../input.log |, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
A::try = A::try + 1;
|
|
if (9 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
|
|
done
|