mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Merge pull request #395 from Security-Onion-Solutions/fix/zeek_extracted
Fix/zeek extracted
This commit is contained in:
@@ -124,3 +124,6 @@ redef LogAscii::json_timestamps = JSON::TS_ISO8601;
|
|||||||
|
|
||||||
# BPF Configuration
|
# BPF Configuration
|
||||||
@load securityonion/bpfconf
|
@load securityonion/bpfconf
|
||||||
|
|
||||||
|
# Extracted files
|
||||||
|
@load securityonion/file-extraction
|
||||||
|
|||||||
@@ -16,6 +16,6 @@ event file_sniff(f: fa_file, meta: fa_metadata)
|
|||||||
if ( meta?$mime_type )
|
if ( meta?$mime_type )
|
||||||
ext = ext_map[meta$mime_type];
|
ext = ext_map[meta$mime_type];
|
||||||
|
|
||||||
local fname = fmt("/nsm/bro/extracted/%s-%s.%s", f$source, f$id, ext);
|
local fname = fmt("/nsm/zeek/extracted/%s-%s.%s", f$source, f$id, ext);
|
||||||
Files::add_analyzer(f, Files::ANALYZER_EXTRACT, [$extract_filename=fname]);
|
Files::add_analyzer(f, Files::ANALYZER_EXTRACT, [$extract_filename=fname]);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user