mirror of
https://github.com/zeek/zeek.git
synced 2025-10-04 23:58:20 +00:00
1288 lines
22 KiB
Text
1288 lines
22 KiB
Text
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-42]
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-42]
|
|
Right
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
==========SERVERS============
|
|
{
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}
|
|
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-43]
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-43]
|
|
Right
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
==========SERVERS============
|
|
{
|
|
[-43] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}
|
|
============PREDICATE============
|
|
Input::EVENT_CHANGED
|
|
[i=-43]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_CHANGED
|
|
Left
|
|
[i=-43]
|
|
Right
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
==========SERVERS============
|
|
{
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}
|
|
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-44]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-45]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-46]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-47]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_NEW
|
|
[i=-48]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-46] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-44] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-47] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-45] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-44]
|
|
Right
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-46] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-44] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-47] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-45] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-45]
|
|
Right
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-46] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-44] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-47] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-45] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-46]
|
|
Right
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-46] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-44] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-47] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-45] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-47]
|
|
Right
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
[source=../input.log, reader=Input::READER_ASCII, mode=Input::REREAD, name=ssh, destination={
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-46] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-44] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-47] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-45] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}, idx=<no value description>, val=<no value description>, want_record=T, ev=line
|
|
{
|
|
print A::outfile, ============EVENT============;
|
|
print A::outfile, Description;
|
|
print A::outfile, A::description;
|
|
print A::outfile, Type;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, Left;
|
|
print A::outfile, A::left;
|
|
print A::outfile, Right;
|
|
print A::outfile, A::right;
|
|
}, pred=anonymous-function
|
|
{
|
|
print A::outfile, ============PREDICATE============;
|
|
print A::outfile, A::typ;
|
|
print A::outfile, A::left;
|
|
print A::outfile, A::right;
|
|
return (T);
|
|
}]
|
|
Type
|
|
Input::EVENT_NEW
|
|
Left
|
|
[i=-48]
|
|
Right
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
==========SERVERS============
|
|
{
|
|
[-43] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-46] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-44] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-47] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-45] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]],
|
|
[-42] = [b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}
|
|
============PREDICATE============
|
|
Input::EVENT_REMOVED
|
|
[i=-43]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_REMOVED
|
|
[i=-46]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_REMOVED
|
|
[i=-44]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_REMOVED
|
|
[i=-47]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_REMOVED
|
|
[i=-45]
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============PREDICATE============
|
|
Input::EVENT_REMOVED
|
|
[i=-42]
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
============EVENT============
|
|
Description
|
|
Input::EVENT_REMOVED
|
|
Type
|
|
[i=-43]
|
|
Left
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
Right
|
|
============EVENT============
|
|
Description
|
|
Input::EVENT_REMOVED
|
|
Type
|
|
[i=-46]
|
|
Left
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
Right
|
|
============EVENT============
|
|
Description
|
|
Input::EVENT_REMOVED
|
|
Type
|
|
[i=-44]
|
|
Left
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
Right
|
|
============EVENT============
|
|
Description
|
|
Input::EVENT_REMOVED
|
|
Type
|
|
[i=-47]
|
|
Left
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
Right
|
|
============EVENT============
|
|
Description
|
|
Input::EVENT_REMOVED
|
|
Type
|
|
[i=-45]
|
|
Left
|
|
[b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
Right
|
|
============EVENT============
|
|
Description
|
|
Input::EVENT_REMOVED
|
|
Type
|
|
[i=-42]
|
|
Left
|
|
[b=T, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
Right
|
|
==========SERVERS============
|
|
{
|
|
[-48] = [b=F, e=SSH::LOG, c=21, p=123/unknown, sn=10.0.0.0/24, a=1.2.3.4, d=3.14, t=1315801931.273616, iv=100.0, s=hurz, sc={
|
|
2,
|
|
4,
|
|
1,
|
|
3
|
|
}, ss={
|
|
CC,
|
|
AA,
|
|
BB
|
|
}, se={
|
|
|
|
}, vc=[10, 20, 30], ve=[]]
|
|
}
|
|
done
|