Hi all,
Recently I have some problems with Bro and PF_RING in cluster.
On my server, when I have less than 32 worker threads(rings),
everything is okay, but when I use worker threads more than 32, pf_ring
start to receive repeating data packets. For example, rings less than 32, I
send 400000 packets to server and pf_ring info in /proc shows there is
400000 packets in rings, but when rings greater than 32, I can get 800000
packets when 33 rings and 1200000 packets when 34 rings and so on.
I guess if there is some rules that a pf_ring or a bro cluster can only
support less than 32 rings or worker threads on a server or some other
reasons?
Any insight would be helpful.
Are there any plans to use another communication platform besides IRC? To
the best of my knowledge the IRC channel does not record history, so any
new member is unaware of prior chats / discoveries.
Is there a desire in the community to move to something along the lines of
Discord or Slack? Granted Slack would come at a premium.
Hi,
I am trying to understand the behavior of bro with respect to logging http
request when the http request has a large body.
In my script, I am trying to log http body. I agree, http bodies can be
large. However, I need the body for further parsing and analysis of traffic
based on the content of the body content. To capture the body, I am setup
events for http_entity_data and http_end_entity. In the 'http_entity_data'
event, I am accumulating the body data into a request variable. In the
end_entity event I am encoding body data using base64_encode (since body
can include non printable characters).
This seems to work fine for small bodies. However, for large bodies, I
noticed that the log gets written without the body getting encoded. To
debug, I added a log filter. In the log predicate call, I can see the http
log writing happening before the end_entity even is called.
Is this how it's supposed to work?
Hi all,
The LT Meeting minutes from the 26 July 2019 LT Meeting are now available
at: https://blog.zeek.org/2019/07/open-source-zeek-leadership-team.html
Please let me know if you have any questions.
Thanks,
~Amber
PS - Don't forget registration for ZeekWeek is still open -
https://www.zeekweek.com
--
*Amber Graner*
Director of Community
Corelight, Inc
828.582.9469
* Ask me about how you can participate in the Zeek (formerly Bro)
community.
* Remember - ZEEK AND YOU SHALL FIND!!
Hi everybody,
there are a number of scripts (known_services, known_hosts, known_certs) which are implemented both using a broker store and sending broker events. It is possible to switch from one mode to the other using the option use_service_store.
Is there any particular reason for this? Is one option more efficient than the other?
Thanks,
Mauro
Hi all,
ZeekWeek 2019 Call for Papers ends tonight. There's still a few hours left
to get that talk in.
Submission Link - http://bit.ly/zeekweek19talksubmission
Thanks,
~Amber
--
*Amber Graner*
Director of Community
Corelight, Inc
828.582.9469
* Ask me about how you can participate in the Zeek (formerly Bro)
community.
* Remember - ZEEK AND YOU SHALL FIND!!
Hi all,
Various organizations are considering sponsoring a series of single-day
Zeek User Workshops across multiple geographies, starting in Atlanta, GA
this fall.
I've created a short (7 question) survey poll to find out what topics are
of interest to you. This will allow me work with the sponsoring
organizations to provide the most relevant content.
Please take a moment to give your feedback -
https://www.surveymonkey.com/r/G7PLPDZ
Also if you or your organization would like to host a Zeek Event, please
let me know.
Thanks,
~Amber
--
*Amber Graner*
Director of Community
Corelight, Inc
828.582.9469
* Ask me about how you can participate in the Zeek (formerly Bro)
community.
* Remember - ZEEK AND YOU SHALL FIND!!
Hi all,
I'm excited to announce the Zeek Package Contest.
- Are you a Zeek user?
- Do you enjoy writing Zeek scripts?
- Do you like being recognized for your awesome work?
- Do you want to make the world’s networks safer?
- Do you like winning prizes and claiming bragging rights?
- Do you want the opportunity to present your work at Zeek events?
More information and details on how you can participate can be found on the
Zeek Blog at:
https://blog.zeek.org/2019/07/zeek-package-contest_25.html
Please let us know if you have any questions.
Thanks,
~Amber
--
*Amber Graner*
Director of Community
Corelight, Inc
828.582.9469
* Ask me about how you can participate in the Zeek (formerly Bro)
community.
* Remember - ZEEK AND YOU SHALL FIND!!