[Zeek-Dev] connection $history - 'g' for gap

Vern Paxson vern at corelight.com
Mon Apr 8 13:02:17 PDT 2019

I'm finding it would be handy to be able to glance at a connection log line
and know that the analysis for the connection experienced a content gap.
For example, this can immediately explain why DPD failed to identify a
known server.

Proposal: add 'g'/'G' connection history values, scaled in the same
exponential way as for 'c', 't' and 'w'.

Any thoughts/objections before I go ahead and implement this?


More information about the zeek-dev mailing list