[Zeek] Testing modules/policies
vlad at es.net
Tue May 19 06:28:17 PDT 2020
On Tue, May 19, 2020 at 7:10 AM Mauricio Tavares <raubvogel at gmail.com>
> 2. Is there a verbose option (I am thinking on the -v[v[v]] in
> ansible/ssh) when you call
> zeek -r pcap policy
> I do not mean the -d option, as it seems to behave like gdb.
One option I use is `zeek -r pcap misc/dump-events my-test-policy.zeek`.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Zeek