[Bro] Multiple Intel framework hits for same connection?

Aaron Gee-Clough lists at g-clef.net
Fri Sep 19 12:57:51 PDT 2014


Hello, all,

I have a question about the intel framework: if a flow matches both an 
Intel::ADDR and Intel::CERT_HASH (for example), will the intel framework 
generate notice logs for both matches, or just one?

Right now it looks like it's just flagging on one, but I'd like to make 
sure I haven't done something wrong.

Thanks.

aaron



More information about the Bro mailing list