[Bro] TCP idle timer expiry

Jaya Dhanesh dhanesh at tataelxsi.co.in
Fri Dec 1 01:34:48 PST 2006



Hi,

If the tcp connection is idle for some time, the connection_state_remove
event handler is getting called.
So the subsequent packets in the same connection doesn't get logged.

How can I increase the tcp idle time out? The increase in the timer is also
not the best solution.
Is there a way where the packets gets logged even after BRO removes the
connection from the table?

Thanks,
Dhanesh.




More information about the Bro mailing list