Zeek script to look for first few packets

Manju Lalwani <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CACNP10iK6TCOvby_1jy=sov0U6RkK+wXhtKmRkrLmY17Hv-W4w@mail.gmail.com>
how can I make Zeek look for the first ten packets only  in a tcp session ?
The first ten packets are enough to fingerprint the traffic I am trying to
identify and so would like to ensure my script  looks at only the first 10
packets to save processing time.

Also the communication can be identified based on 7 packets immediately
following the tcp handshake and using a custom service not categorised by
zeek.. tcp_packet event has been the closest match for my script . Is there
any Zeek event that can be a better match for this communication ?

Thanks in advance,
Manju

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.