[Bro] BPF packet filter syntax

Corey Roach (ISO) Corey.Roach at utah.edu
Tue Aug 28 06:50:08 PDT 2012


On Aug 27, 2012, at 11:34 PM, Seth Hall <seth at icir.org> wrote:

> One funny thing is that I was *really* surprised that this syntax works.  Normally I would surround the table values with curly braces like this…

> At some point we're really going to have to tighten up the language's use of curly braces and square brackets, there is still a lot of inconsistency floating around.

Ha! That'll teach me to copy-and-paste from the list without paying attention to syntax...

I fixed the square-brackets to curly-brackets, but it did not see to fix the problem. I'll dig around and send you some logs offline as soon as I get a chance.

Thanks!





More information about the Bro mailing list