[Bro] Filenames not extracted in files.log

Bob Probert bruisebrotherprobert at gmail.com
Tue Apr 29 14:49:04 PDT 2014


Hi all,

After looking at an aggregate 30 days of files.log in Splunk, I noticed
that 98% of the files identified by Bro have no filenames associated with
them.

While I haven't done any rigorous testing of this, it just seems wrong. Is
this a known bug? Is anyone else experiencing this?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20140429/a29f36e1/attachment.html 


More information about the Bro mailing list