Re: Creating a module and accessing an event in another script

Merril Mathew <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAPqihfz6WudZnZ3JjnrTZd8vEMqZ3eG1_f_BXEJ4dUzraP-QQg@mail.gmail.com>
Hi Justin,

Now it sends the email. But it executes the "if(!rec?$auth_success)"
condition and I am getting message "unknown". Which means auth_success is
not found on live traffic, so the error remains I think.

Kind regards,
Merril.

On Wed, 5 Jun 2019, 18:39 Justin Azoff, <[email protected]> wrote:

> that script should generally work, but it was a lot more complicated than
> it needed to be to accomplish what you are trying to do.  Here is a much
> simplified version.
>
> The only thing to keep in mind is that since you are using zeek_init to
> setup the log stream this won't work on bro or a small number of zeek
> builds from right after the rename.  There are no released versions of zeek
> so I don't know when you built it.  Using bro_init is backwards compatible
> and is probably better for now.
>
> On Wed, Jun 5, 2019 at 12:46 PM Merril Mathew <[email protected]>
> wrote:
>
>> Hi Justin,
>>
>> I can confirm that attached scripts does not send me email on live
>> traffic or create a log under $PREFIX/logs/current. But it does create
>> notice.log and a SSHAttempt.log when running pcap. I can also confirm that
>> send mail set up is working as I have received emails from zeek from other
>> scripts.
>>
>> Kind regards,
>> Merril.
>>
>>
>>
>> On 5 Jun 2019, at 17:20, Justin Azoff <[email protected]> wrote:
>>
>> On Wed, Jun 5, 2019 at 12:11 PM Merril Mathew <
>> [email protected]> wrote:
>>
>>> Hi Justin,
>>>
>>> Thanks. But it did not work for me.
>>>
>>
>> Did not work how?  Did you post the version of the script that didn't
>> work?
>>
>> --
>> Justin
>>
>>
>>
>
> --
> Justin
>

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.