Event namespaces
Jeff Barber <[email protected]> Wed, 23 Oct 2019 12:31:17 -0600
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CABLqKG+Ac23EfmooQZxTveVLA60qxfc3W_R9nvLwWVoEKzvSYQ@mail.gmail.com> |
At https://docs.zeek.org/en/stable/frameworks/broker.html#a-reminder-about-events-and-module-namespaces, following a code sample, there is the statement: *This code runs without errors, however, the local my_event handler will never be called and also not any remote handlers either, even if Broker::auto_publish was used elsewhere for it. * My tests have not supported that assertion: the event handler is invoked - even via auto_publish. If it is so, how/when exactly would it manifest? Are there other factors that might cause it to be true in some cases? (Say, the same event name in a different namespace?) Just trying to figure out how careful I need to be of namespace issues. My tests have generally shown that if you get the namespace of some script element wrong, the script parsing stage gives you an 'undefined' right out of the gate. Thanks, Jeff _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek