[Bro] [bro] smtp log strangeness

Tim Desrochers tgdesrochers at gmail.com
Fri Mar 25 05:21:19 PDT 2016


While parsing smpt logs I notice a bunch of strange data contained in my from/to/subject fields

Example:
"subject":"=?utf-8?q?CBO_drops_the_March_base=E2=80=A6line?="
"subject":"=?Windows-1252?Q?Automatic_reply:_CBO_drops_the_March_base=85line?=",
"from":"\u0022NAMEOFPERSON\u0022 <first.middle.last at something.com>"

Why am I getting all of this extra info in these fields?

I am printing logs as JSON not CSV.

Thanks in advance
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20160325/2d349ea3/attachment.html 


More information about the Bro mailing list