zeek/scripts/policy/frameworks
Johanna Amann af77a7a83b Analyzer failure logging: tweaks and test fixes
The main part of this commit are changes in tests. A lot of the tests
that previously relied on analyzer.log or dpd.log now use the new
analyzer-failed.log.

I verified all the changes and, as far as I can tell, everything
behaves as it should. This includes the external test baselines.

This change also enables logging of file and packet analyzer to
analyzer_failed.log and fixes some small behavior issues.

The analyzer_failed event is no longer raised when the removal of an
analyzer is vetoed.

If an analyzer is no longer active when an analyzer violation is raised,
currently the analyzer_failed event is raised. This can, e.g., happen
when an analyzer error happens at the very end of the connection. This
makes the behavior more similar to what happened in the past, and also
intuitively seems to make sense.

A bug introduced in the failed service logging was fixed.
2025-06-03 15:56:42 +01:00
..
analyzer Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
cluster cluster/zeromq: Implement DoReadyToPublishCallback() 2025-04-25 09:57:06 +00:00
control frameworks/control: Remove Broker::auto_publish() 2024-11-14 12:59:22 +01:00
dpd Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
files Remove full scripts marked as 6.1 deprecations 2023-06-14 10:07:22 -07:00
intel intel/seen/manage-event-groups: Policy script for toggling intel event groups 2025-06-02 09:51:14 +02:00
management broker/main: Deprecate Broker::listen_websocket() 2025-04-23 14:27:43 +02:00
netcontrol netcontrol/catch-and-release: Move to Cluster::publish() 2024-12-12 17:54:42 +01:00
notice policy/community-id: Populate conn$community_id in new_connection() 2024-11-08 18:19:55 +01:00
packet-filter Fix errors from rst linting on the generated docs 2025-01-24 11:41:36 -07:00
signatures signatures/iso-9660: Add \x01 suffix to CD001 2024-02-26 21:00:01 +01:00
software policy: Use literal dots for patterns used against content-type and hostname 2022-07-11 10:34:47 +02:00
spicy all: Fix typos identified by typos pre-commit hook 2023-06-13 17:57:32 +02:00
storage/backend SQLite: Move integrity_check to pragma table 2025-05-21 09:38:27 -07:00
telemetry Fix errors from rst linting on the generated docs 2025-01-24 11:41:36 -07:00