Re: Event namespaces
Jim Mellander <[email protected]> Wed, 23 Oct 2019 12:15:17 -0700
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CADju=b5tvWnCxSHKuf28d=h8JRsxO0y42tmj+v0qdBoHoqUizg@mail.gmail.com> |
Take a look at these: https://github.com/zeek/zeek/issues/163 & https://bro-tracker.atlassian.net/browse/BIT-984 I've run into this issue, and my best practice is to use fully scoped event names, which is the recommended workaround. Jim On Wed, Oct 23, 2019 at 11:34 AM Jeff Barber <[email protected]> wrote: > At > https://docs.zeek.org/en/stable/frameworks/broker.html#a-reminder-about-events-and-module-namespaces, > following a code sample, there is the statement: > > *This code runs without errors, however, the local my_event handler will > never be called and also not any remote handlers either, even if > Broker::auto_publish was used elsewhere for it. * > > > My tests have not supported that assertion: the event handler is invoked - > even via auto_publish. If it is so, how/when exactly would it manifest? Are > there other factors that might cause it to be true in some cases? (Say, the > same event name in a different namespace?) > > Just trying to figure out how careful I need to be of namespace issues. My > tests have generally shown that if you get the namespace of some script > element wrong, the script parsing stage gives you an 'undefined' right out > of the gate. > > Thanks, > Jeff > > _______________________________________________ > Zeek mailing list > [email protected] > http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek