mirror of
https://github.com/zeek/zeek.git
synced 2025-10-07 00:58:19 +00:00

If a test doesn't rely on libmagic, mime type related columns of baselined logs are filtered out. If a test does rely on libmagic, it needs to use the TEST-REQUIRES btest macro to check that the bro build supports it, and then mime type related columns of logs can be normalized via a logging filter to reduce sensitivity to varying version of libmagic.
5 lines
629 B
Text
5 lines
629 B
Text
# ts uid id.orig_h id.orig_p id.resp_h id.resp_p nick user channels command value addl tags dcc_file_name dcc_file_size extraction_file
|
|
1311189164.119437 UWkUyAuUGXf 192.168.1.77 57640 66.198.80.67 6667 - - - NICK bloed - - - - -
|
|
1311189164.119437 UWkUyAuUGXf 192.168.1.77 57640 66.198.80.67 6667 bloed - - USER sdkfje sdkfje Montreal.QC.CA.Undernet.org dkdkrwq - - - -
|
|
1311189174.474127 UWkUyAuUGXf 192.168.1.77 57640 66.198.80.67 6667 bloed sdkfje - JOIN #easymovies - - - - -
|
|
1311189316.326025 UWkUyAuUGXf 192.168.1.77 57640 66.198.80.67 6667 bloed sdkfje - DCC #easymovies - - ladyvampress-default(2011-07-07)-OS.zip 42208 -
|