[Bro] Off-line analysis

Vern Paxson vern at icir.org
Sun Dec 5 16:49:35 PST 2004


> I first have to make "my own".bro, and then add the "my own.bro" file to
> policy setting in bro.cfg?

No, bro.cfg is for (somewhat) turnkey operational use.  For your
own offline analysis, you should ignore it and just create your
own file my-own.bro and then use

	bro -r tracefile my-own

to process it.

		Vern



More information about the Bro mailing list