zeek/scripts/spicy
Robin Sommer cdadd934ce
[Spicy] Extend functionality of export in EVT files.
We now support selecting which fields of a unit type get exported into
the automatically created Zeek record; as well as selecting which
fields get a `&log` attribute added automatically to either all fields
or to selected fields.

Syntax:

- To export only selected fields:

    export Foo::X with { field1, field3 };

- To export all but selected fields:

    export Foo::X without { field2, field3 };

- To `&log` all fields:

    export Foo::X &log;

- To `&log` only selected fields:

    export Foo::X with { field1 &log, field3 }; # exports (only) field1 and field3, and marks field1 for logging

Syntax is still subject to change.

Closes #3218.
Closes #3219.
2023-08-21 10:26:25 +02:00
..
zeek.spicy Integrate the Spicy plugin into Zeek proper. 2023-05-16 10:17:45 +02:00
zeek_file.spicy Integrate the Spicy plugin into Zeek proper. 2023-05-16 10:17:45 +02:00
zeek_rt.hlt [Spicy] Extend functionality of export in EVT files. 2023-08-21 10:26:25 +02:00