mirror of
https://github.com/zeek/zeek.git
synced 2025-10-03 15:18:20 +00:00
44 lines
1.3 KiB
Text
44 lines
1.3 KiB
Text
##! This script handles core generated connection related "weird" events to
|
|
##! push weird information about connections into the weird framework.
|
|
##! For live operational deployments, this can frequently cause load issues
|
|
##! due to large numbers of these events and quite possibly shouldn't be
|
|
##! loaded.
|
|
|
|
@load base/frameworks/notice
|
|
|
|
module Conn;
|
|
|
|
export {
|
|
redef enum Notice::Type += {
|
|
## Possible evasion; usually just chud.
|
|
Retransmission_Inconsistency,
|
|
## Could mean packet drop; could also be chud.
|
|
Ack_Above_Hole,
|
|
## Data has sequence hole; perhaps due to filtering.
|
|
Content_Gap,
|
|
};
|
|
}
|
|
|
|
event rexmit_inconsistency(c: connection, t1: string, t2: string)
|
|
{
|
|
NOTICE([$note=Retransmission_Inconsistency,
|
|
$conn=c,
|
|
$msg=fmt("%s rexmit inconsistency (%s) (%s)",
|
|
id_string(c$id), t1, t2),
|
|
$identifier=fmt("%s", c$id)]);
|
|
}
|
|
|
|
event ack_above_hole(c: connection)
|
|
{
|
|
NOTICE([$note=Ack_Above_Hole, $conn=c,
|
|
$msg=fmt("%s ack above a hole", id_string(c$id))]);
|
|
}
|
|
|
|
event content_gap(c: connection, is_orig: bool, seq: count, length: count)
|
|
{
|
|
NOTICE([$note=Content_Gap, $conn=c,
|
|
$msg=fmt("%s content gap (%s %d/%d)%s",
|
|
id_string(c$id), is_orig ? ">" : "<", seq, length,
|
|
is_external_connection(c) ? " [external]" : "")]);
|
|
}
|
|
|