[Bro-Dev] $tag in notice_info

Vern Paxson vern at icir.org
Tue Mar 8 00:33:15 PST 2011

> I'm actually not sure how helpful having the tag is, I don't think
> I've ever used the tag but always grep for the 4-tuple right away.

Hmmm, I think I not-uncommonly grep on the tag to map from a notice.log
entry to a conn.log entry, unless I'm missing some context here.

That said, having a more general connection identifier, as subsequently
discussed, would work for this, too.


