[Bro] email alerts

Daniel Thayer dnthayer at illinois.edu
Tue Jan 10 12:04:13 PST 2017


On 1/10/17 1:35 PM, Andrew Dellana wrote:
> Hello,
>
>
>
> We have email alerts configured (connection summary and dropped packets)
> to be emailed on the hour they worked for several weeks, but over the
> past few days we have not received any. Is there a reason for these not
> showing up?
>

Did you check if the connection summary reports are being created?
The connection summary reports are stored along with your other log 
files.  Try this:
ls -l /usr/local/bro/logs/2017-01-10/conn-summary*



More information about the Bro mailing list