Re: Using "dbl" instead of "num" in SumStats

"Hui Lin (Hugo)" <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAKq214nA0bDHTPGTpTS3XEOUasNWNUSWTN8hi4WKDvuFBrCihw@mail.gmail.com>
Hi Jim,

I think 'num' field seemed like what I am looking for. However, when I
tried, it is different from the count that I manually made. Here is the
codes that I used to count. As you can see, what I try to is easy,
whenever, an observation is received, I increase the value of a global
value. However, when I print out through epoch call back function, the
value is different from one in 'num'.

if (...)
     {
     total_res = total_res + 1;
     SumStats::observe("dnp3 rtt", SumStats::Key(),
SumStats::Observation($dbl=latency));
     }


Best,

Hugo

On Mon, May 6, 2019 at 9:16 AM Jim Mellander <[email protected]> wrote:

> Hi Hugo:
>
> <snip>
> May I suggest a few things in SumStats? Maybe I missed something, I don't
> know how to directly obtain the number of data recorded in SumStats, so I
> need to declare another global variable to record that. It will be useful
> that we can directly know how many data are recorded by far. The reason
> that I need the number of records is to calculate the 95% or 99% confidence
> interval. It will be great that we can include them directly in SumStats as
> well.
> <snip>
>
> Each result record returned to epoch_result has a 'num' field, which is a
> count of the number of observations that made up that result - is that what
> you're looking for?  If you're looking for a grand total of observations, I
> suppose they could be totalled up from the result records.
>
> Take care,
>
> JIm
>
>

-- 
Hui Lin
Ph.D. Candidate (http://hlin33.web.engr.illinois.edu/)
DEPEND (http://depend.csl.illinois.edu/)
ECE, Uni. of Illinois at Urbana-Champaign

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.