mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

Converted hard-coded examples in the File Analysis framework document to using btest sphinx.
20 lines
385 B
Text
20 lines
385 B
Text
event connection_state_remove(c: connection)
|
|
{
|
|
print "connection_state_remove";
|
|
print c$uid;
|
|
print c$id;
|
|
for ( s in c$service )
|
|
print s;
|
|
}
|
|
|
|
event file_state_remove(f: fa_file)
|
|
{
|
|
print "file_state_remove";
|
|
print f$id;
|
|
for ( cid in f$conns )
|
|
{
|
|
print f$conns[cid]$uid;
|
|
print cid;
|
|
}
|
|
print f$source;
|
|
}
|