blacktop
(Blacktop)
January 4, 2017, 7:15pm
1
I have a question about the built-in bro grok patterns.
In Bro you can greatly change the fields that are present depending on what scripts/mods/policies you load.
When you look at their log-file docs MOST of the fields are optional. So can grok really do a comprehensive job labeling the fields?
Any help greatly appreciated
More Info: Question about creating Brobeat
blacktop
(Blacktop)
January 4, 2017, 7:33pm
2
blacktop
(Blacktop)
January 7, 2017, 2:19am
3
More clarification: when I stood up a simple test with BRO_HTTP and my logs I saw that it was incorrectly parsing them.
system
(system)
Closed
February 4, 2017, 2:20am
4
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.