zeek/policy/frameworks/cluster/base/node/worker.bro
2011-07-15 01:11:37 -04:00

18 lines
No EOL
540 B
Text

@prefixes += cluster-worker
## Don't do any local logging.
redef Log::enable_local_logging = F;
## Make sure that remote logging is enabled.
redef Log::enable_remote_logging = T;
## Use the cluster's delete-log script.
redef Log::default_rotation_postprocessor = "delete-log";
## Record all packets into trace file.
# TODO: should we really be setting this to T?
redef record_all_packets = T;
# TODO: Workers need to have a filter for the notice log which doesn't
# do remote logging since we forward the notice event directly.