[Bro] scripting a notice based on software framework

John Babio jbabio at po-box.esu.edu
Tue Dec 3 18:05:39 PST 2013


I was wondering if someone could help me out. I am looking to write a test script based on data logged to the software.log. I want to create a notice for a regex string match from the unparsed_version. I was going to use the intel framework but I have to match the entire string.




More information about the Bro mailing list