mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00

with the same userinterface as in the logging interface. Not really tested, but tests still work.
136 lines
2.8 KiB
Text
136 lines
2.8 KiB
Text
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
sdfkh:KH;fdkncv;ISEUp34:Fkdj;YVpIODhfDF
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
DSF"DFKJ"SDFKLh304yrsdkfj@#(*U$34jfDJup3UF
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
q3r3057fdf
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
sdfs\d
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
dfsdf
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
sdf
|
|
[source=../input.log, reader=Input::READER_RAW, mode=Input::STREAM, name=input, fields=<no value description>, want_record=F, ev=line
|
|
{
|
|
print A::outfile, A::description;
|
|
print A::outfile, A::tpe;
|
|
print A::outfile, A::s;
|
|
if (3 == A::try)
|
|
{
|
|
print A::outfile, done;
|
|
close(A::outfile);
|
|
Input::remove(input);
|
|
}
|
|
|
|
}, config={
|
|
|
|
}]
|
|
Input::EVENT_NEW
|
|
3rw43wRRERLlL#RWERERERE.
|