[Bro] File log

Paul Halliday paul.halliday at gmail.com
Wed Oct 1 06:32:43 PDT 2014


Is it normal for the 'filename' field to always be empty? The mime_type is
almost always identified but the filename field is always '-'

application/vnd.ms-cab-compressed -
application/x-dosexec -
text/plain -
application/x-dosexec -
text/plain -
application/vnd.ms-fontobject -
application/vnd.ms-fontobject -
application/vnd.ms-fontobject -
application/octet-stream -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/x-dosexec -
application/vnd.ms-cab-compressed -
image/jpeg -
image/jpeg -
image/jpeg -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/x-dosexec -
application/vnd.ms-cab-compressed -
text/plain -
text/html -
text/html -
application/x-dosexec -
application/vnd.ms-cab-compressed -
application/x-dosexec -
application/vnd.ms-cab-compressed -
application/x-dosexec -
image/jpeg -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/x-dosexec -
text/plain -
image/jpeg -
application/vnd.ms-cab-compressed -
application/octet-stream -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
image/jpeg -
image/jpeg -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
image/jpeg -
application/x-dosexec -
application/x-dosexec -
application/vnd.ms-cab-compressed -
application/vnd.ms-cab-compressed -
text/html -
text/html -

Thanks.

-- 
Paul Halliday
http://www.pintumbler.org/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20141001/b3e2d6de/attachment.html 


More information about the Bro mailing list