[Bro] Basic questions about the use of Bro.
renaud.luca at gmail.com
Sat Apr 5 14:43:50 PDT 2008
How can I get the output of Bro in normal time and not UNIX time,using cf.
for example,processing a tcpdump capture file:
/usr/local/bro-1.2/bin/bro -r tcpdumpfile ,I get a list of weird events
in UNIX time,and I prefer normal time.
I did not do a complete installation of Bro,I use Bro to analyze my home
ADSL connections right after the end of the session,so Bro does not report
to log files in the logs directory,it reports to standard output.
When I analyze dump files:
/usr/local/bro-1.2/bin/bro -r tcpdumpcapturefile so far I get a list of
etc.,which by itself is not specially troublesome.My question is:
if bro ever needs to report more troublesome events,does it follow
the same terminology(name) used for the diverse files in the logs
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro