[Bro] Summary Reports and service listing

Harry Hoffman hhoffman at ip-solutions.net
Fri Sep 20 05:58:30 PDT 2013


Hi All,

The summary reports that are emailed hourly contain service listings
(e.g. port 80 HTTP).

Are there processors that match the service to the port based upon
packets seen or is this just based off of /etc/services or the like?

I ask as syslog is being noted on port 514 but not being noted as syslog.

Cheers,
Harry




More information about the Bro mailing list