[Bro] fa_file SMTP::Info

Albert Zaharovits albert.zaharovits at gmail.com
Fri Jul 17 07:32:17 PDT 2015


When a file is downloaded over HTTP there is a fa_file$http  HTTP::Info struct.

I wonder why there is no fa_file$smtp SMTP::Info struct when the file is over a SMTP connection? Why do I need to loop the connections table for the SMTP::Info struct?


More information about the Bro mailing list