您的位置:首页 > 其它

Bro脚本语法6-日志文件(Log Files)

2016-10-26 17:21 393 查看

Bro脚本语法6-日志文件(Log Files)

@(教程)[Bro]

Network Protocols

Log FileDescriptionField Descriptions
conn.logTCP/UDP/ICMP connectionsConn::Info
dhcp.logDHCP leasesDHCP::Info
dnp3.logDNP3 requests and repliesDNP3::Info
dns.logDNS activityDNS::Info
ftp.logFTP activityFTP::Info
http.logHTTP requests and repliesHTTP::Info
irc.logIRC commands and responsesIRC::Info
kerberos.logKerberosKRB::Info
modbus.logModbus commands and responsesModbus::Info
modbus_register_change.logTracks changes to Modbus holding registersModbus::MemmapInfo
mysql.logMySQLMySQL::Info
radius.logRADIUS authentication attemptsRADIUS::Info
rdp.logRDPRDP::Info
rfb.logRemote Framebuffer (RFB)RFB::Info
sip.logSIPSIP::Info
snmp.logSNMP messagesSNMP::Info
socks.logSOCKS proxy requestsSOCKS::Info
ssh.logSSH connectionsSSH::Info
ssl.logSSL/TLS handshake infoSSL::Info
syslog.logSyslog messagesSyslog::Info
tunnel.logTunneling protocol eventsTunnel::Info
Files

Log FileDescriptionField Descriptions
files.logFile analysis resultsFiles::Info
pe.logPortable Executable (PE)PE::Info
x509.logX.509 certificate infoX509::Info
NetControl

Log FileDescription FieldDescriptions
netcontrol.logNetControl actionsNetControl::Info
netcontrol_drop.logNetControl actionsNetControl::DropInfo
netcontrol_shunt.logNetControl shunt actionsNetControl::ShuntInfo
netcontrol_catch_release.logNetControl catch and release actionsNetControl::CatchReleaseInfo
openflow.logOpenFlow debug logOpenFlow::Info
Detection

Log FileDescriptionField Descriptions
intel.logIntelligence data matchesIntel::Info
notice.logBro noticesNotice::Info
notice_alarm.logThe alarm streamNotice::ACTION_ALARM
signatures.logSignature matchesSignatures::Info
traceroute.logTraceroute detectionTraceroute::Info
Network Observations

Log FileDescriptionField Descriptions
known_certs.logSSL certificatesKnown::CertsInfo
known_devices.logMAC addresses of devices on the networkKnown::DevicesInfo
known_hosts.logHosts that have completed TCP handshakesKnown::HostsInfo
known_modbus.logModbus masters and slavesKnown::ModbusInfo
known_services.logServices running on hostsKnown::ServicesInfo
software.logSoftware being used on the networkSoftware::Info
Miscellaneous

Log FileDescriptionField Descriptions
barnyard2.logAlerts received from Barnyard2Barnyard2::Info
dpd.logDynamic protocol detection failuresDPD::Info
unified2.logInterprets Snort’s unified outputUnified2::Info
weird.logUnexpected network-level activityWeird::Info
Bro Diagnostics

Log FileDescriptionField Descriptions
capture_loss.logPacket loss rateCaptureLoss::Info
cluster.logBro cluster messagesCluster::Info
communication.logCommunication events between Bro or Broccoli instancesCommunication::Info
loaded_scripts.logShows all scripts loaded by BroLoadedScripts::Info
packet_filter.logList packet filters that were appliedPacketFilter::Info
prof.logProfiling statistics (to create this log, load policy/misc/profiling.bro)N/A
reporter.logInternal error/warning/info messagesReporter::Info
stats.logMemory/event/packet/lag statisticsStats::Info
stderr.logCaptures standard error when Bro is started from BroControlN/A
stdout.logCaptures standard output when Bro is started from BroControlN/A
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签:  脚本