zeek/testing/btest/scripts/base/protocols
Johanna Amann af77a7a83b Analyzer failure logging: tweaks and test fixes
The main part of this commit are changes in tests. A lot of the tests
that previously relied on analyzer.log or dpd.log now use the new
analyzer-failed.log.

I verified all the changes and, as far as I can tell, everything
behaves as it should. This includes the external test baselines.

This change also enables logging of file and packet analyzer to
analyzer_failed.log and fixes some small behavior issues.

The analyzer_failed event is no longer raised when the removal of an
analyzer is vetoed.

If an analyzer is no longer active when an analyzer violation is raised,
currently the analyzer_failed event is raised. This can, e.g., happen
when an analyzer error happens at the very end of the connection. This
makes the behavior more similar to what happened in the past, and also
intuitively seems to make sense.

A bug introduced in the failed service logging was fixed.
2025-06-03 15:56:42 +01:00
..
arp Initial implementation of Lower-Level analyzers 2020-09-23 11:13:25 -07:00
bittorrent testing/btest/*zeek: Comment all @TEST lines 2025-04-17 16:30:23 +02:00
conn GH-1252: rename files with colons for Windows compatibility 2020-11-04 10:29:52 -08:00
dce-rpc Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
dhcp btest remaining: Use generic cluster-layout.zeek 2025-05-20 20:30:01 +02:00
dnp3 General btest cleanup 2020-08-11 11:26:22 -07:00
dns Raise warnings when for DNS events that are not raised due to dns_skip_all_addl 2025-01-07 17:46:27 +00:00
finger Provide infrastructure to migrate legacy analyzers to Spicy. 2023-02-01 11:33:48 +01:00
ftp Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
http Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
icmp Remove deprecated ICMP events 2021-01-27 10:52:40 -07:00
imap Remove @load base/frameworks/dpd from tests 2022-08-31 17:00:55 +02:00
irc Add irc_dcc_send_ack event and fix missing fields 2023-04-24 07:29:51 +00:00
krb Make enc_part value from kerberos response available to scripts 2025-01-31 12:58:14 +00:00
ldap Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
modbus Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
mount GH-239: Rename bro to zeek, bro-config to zeek-config, and bro-path-dev to zeek-path-dev. 2019-05-01 21:43:45 +00:00
mqtt Remove full scripts marked as 6.1 deprecations 2023-06-14 10:07:22 -07:00
mysql mysql: Implement and test COM_CHANGE_USER 2024-08-14 10:20:01 +02:00
ncp General btest cleanup 2020-08-11 11:26:22 -07:00
nfs GH-239: Rename bro to zeek, bro-config to zeek-config, and bro-path-dev to zeek-path-dev. 2019-05-01 21:43:45 +00:00
ntp NTP: Detect out-of-order packets 2023-05-04 19:44:02 +02:00
pop3 Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
portmap GH-684: Fix parsing of RPC calls with non-AUTH_UNIX flavors 2019-11-13 13:14:14 -08:00
postgresql Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
quic Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
radius Convert pcapng test suite files to pcap format 2019-11-08 13:08:06 -08:00
rdp Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
redis spicy-redis: Separate error replies from success 2025-05-27 09:31:25 -04:00
rfb regularize test suite names to avoid custom/outdated suffices 2022-05-12 13:32:49 -07:00
sip GH-1507: Tolerate junk data before SIP requests 2021-04-14 15:34:07 -07:00
smb Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
smtp btest/smtp/bdat: Move tests into proper directory 2024-01-23 21:49:50 +01:00
snap Make SNAP analyzer use both OUI and protocol for forwarding 2025-03-24 15:20:50 -07:00
snmp General btest cleanup 2020-08-11 11:26:22 -07:00
socks testing/btest/*zeek: Comment all @TEST lines 2025-04-17 16:30:23 +02:00
ssh Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
ssl Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
syslog General btest cleanup 2020-08-11 11:26:22 -07:00
tcp Add testcase for TCP segment offloading. 2021-11-23 12:37:55 +00:00
websocket Analyzer failure logging: tweaks and test fixes 2025-06-03 15:56:42 +01:00
xmpp Remove @load base/frameworks/dpd from tests 2022-08-31 17:00:55 +02:00