This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/bin/sh | |
# | |
# Wrapper for viewing/setting options that the plugin's CMake | |
# scripts will recognize. | |
# | |
# Don't edit this. Edit configure.plugin to add plugin-specific options. | |
# | |
set -e | |
command="$0 $*" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/usr/bin/env bash | |
# Provide field numbers for valid Bro logs | |
# Author: Keith Lehigh <klehigh@iu.edu> | |
# use bash strict mode | |
set -euo pipefail | |
IFS=$'\n\t' | |
### |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# add peer data to connection records | |
redef record Conn::Info += { | |
peer: string &log &optional; | |
}; | |
event connection_state_remove(c: connection) { | |
if ( c?$conn ) | |
c$conn$peer = peer_description; | |
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- Bro.pm.old 2013-10-09 14:53:40.205618890 +0000 | |
+++ Bro.pm 2013-10-09 13:19:57.575611679 +0000 | |
@@ -16,7 +16,7 @@ | |
my @config_search_path = ('claoverride', $feed->{'query'}, 'client' ); | |
- $result = "#fields\thost\tnet\tstr\tstr_type\tmeta.source\tmeta.desc\tmeta.url\tmeta.cif_impact\tmeta.cif_severity\tmeta.cif_confidence\n"; | |
+ $result = "#fields\tindicator\tindicator_type\tmeta.source\tmeta.desc\tmeta.url\tmeta.cif_impact\tmeta.cif_severity\tmeta.cif_confidence\n"; | |
foreach my $a (@array){ |