[Bro] BRO intel framework
Giedrius Ramas
giedrius.ramas at gmail.com
Tue Apr 28 00:39:35 PDT 2015
Hi all ,
I am using BRO intel framework and have some doubts about intel.dat file .
Currently I have in my script following :
redef Intel::read_files += {
"/opt/bro/share/bro/intel/intel.dat"
};
How can I append data to /intel.dat ? Can I just overwrite it by using mv
linux command ? Is it necessary to reload bro once /intel.dat changed ?
Please shed some light on how bro works with that file .
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20150428/cefd9d2f/attachment.html
More information about the Bro
mailing list