[Bro] Store ASCII and JSON output format at the same time

jose antonio izquierdo lopez jizquierdo at owlh.net
Wed May 9 03:03:48 PDT 2018


Hi Bro Family,

We want to implement a logging configuration with Bro that will allow us to
store the output in both formats at the same time: JSON and ASCII.

The main idea is to have something like:
.- weird.log
.- weird.json

As each filter seems to be able to use one writer, I can't see the way to
accomplish this configuration with current plugins, configs, packets.
Hopefully, I'm wrong.

Does someone know if there is a configuration or packet that can help to
achieve this config?

Thanks a
lo
t,
​
​B
est Regards,

Jose Antonio Izquierdo
m - +34 673 055 255
skype - izquierdo.lopez
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20180509/ffd33e58/attachment.html 


More information about the Bro mailing list