[Bro] scan.bro and missing log entries

Vern Paxson vern at icir.org
Thu Dec 2 08:13:06 PST 2010


> I've been seeing AddressScan alerts, but when I check conn.log, I can't
> find the corresponding entries.

In general with these sorts of problems, it helps hugely if you can supply
a trace that reproduces the problem, and also summarize the command line /
analysis you're using.

		Vern



More information about the Bro mailing list