[Zeek] Testing modules/policies

Mauricio Tavares raubvogel at gmail.com
Tue May 19 05:09:06 PDT 2020


1. I understand that if a module is manually tested (by calling it and
feeding a pcap), its log entries will be saved on the same directory
said module was called from. But, what if the module is also supposed
to mail out? Would it be able to do the deed?

2. Is there a verbose option (I am thinking on the -v[v[v]] in
ansible/ssh) when you call

zeek -r pcap policy

I do not mean the -d option, as it seems to behave like gdb.


More information about the Zeek mailing list