What level of anonymization are you attempting to do?  If your goal is 
to scramble the IP addresses
you can just set anonymize_ip_addr to true (see policy/anon.bro).  If 
you are interested in saniting application
level data, take a look at policy/ftp-anon.bro.  Note that there is a 
bug in the TCP rewriter which keeps
data from being written to the transformation traces (remove the assert 
in TCP_Rewriter.cc line 721
to change it to next_packet->AppendData(data, left); )

and .. of course for rewriting, use -A from the command line.


