[Bro] BRO intel framework

Giedrius Ramas giedrius.ramas at gmail.com
Tue Apr 28 00:39:35 PDT 2015


Hi all ,
I am using BRO intel framework and have some doubts about intel.dat file .
Currently I have in my script following :

redef Intel::read_files += {
        "/opt/bro/share/bro/intel/intel.dat"
};


How can I append data to /intel.dat ? Can I just overwrite it by using mv
linux command ? Is it necessary to reload bro once /intel.dat changed  ?

Please shed some light on how bro works with that file .
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20150428/cefd9d2f/attachment.html 


More information about the Bro mailing list