[Bro] Bro detection scripts updates

Seth Hall seth at icir.org
Wed Mar 11 18:53:54 PDT 2015

> On Mar 11, 2015, at 5:30 PM, Kellogg, Brian D (OLN) <bkellogg at dresser-rand.com> wrote:
> Is this the best way to accomplish this task?  Secondly, if advisable, how do we get these script changes incorporated into Bro base?  I'm not that experienced with git but willing to learn more if needed.  These changes were made, again, to benefit ELSA searching/grouping and for the Bro correlation script recently released.

You might be right in how you’ve done this.  I never felt very comfortable with how this ended up getting implemented.  I’ll file a ticket and see if I can address the ones you’ve pointed out and see if there are anymore.  I’ll probably also mark the src and dst fields as deprecated and maybe do a reporter message if they’re ever used (to give people a bit of breathing room before we break any existing scripts they have).

Here’s the ticket in case you or anyone else wants to comment on it: 

Great suggestion, thanks!

Seth Hall
International Computer Science Institute
(Bro) because everyone has a network

More information about the Bro mailing list