]
Jon Siwek commented on BIT-1119:
--------------------------------
Added a new commit on the branch to add a script which auto-detects/warns about running on
filtered trace.
topic/jsiwek/tcp-improvements
-----------------------------
Key: BIT-1119
URL:
https://bro-tracker.atlassian.net/browse/BIT-1119
Project: Bro Issue Tracker
Issue Type: Improvement
Components: Bro
Affects Versions: git/master
Reporter: Jon Siwek
Fix For: 2.3
Attachments: signature.asc
This branch is in the bro, bro-testing, and bro-testing-private repos and has a few
changes to improve reporting of TCP connection sizes and gaps (commit messages explain in
more detail).
The baseline changes in the external repos all seemed reasonable/explainable (or actually
fix a problem). There's too much changed to go through case-by-case and actually
check things, but I did do closer examinations of unique differences as I came across them
(e.g. try to corroborate Bro results via wireshark). Then for those that seem to follow
the same trend as something I already inspected, I wouldn't manually check.