Welcome to our Bro workshop at EDUCAUSE 2016. This page contains all links and material we use or present during the day.
This workshop is presented by Seth Hall, Vlad Grigorescu, Justin Aszoff, and Doris Schioberg. We all are members of the Bro team.
To meet as many attendees’ needs as possible we keep our agenda for today flexible. Below you find the day’s structure in terms of session and topics.
08:30 | Welcome and Introduction to Bro |
10:00 | Coffee break |
10:30 | Session 2: Navigating in and with Bro |
12:00 | Lunch |
13:00 | Bro in the real world: Bro usage, configuration, tuning and problem solving. Bro Script Tutorial |
14:30 | Coffee break |
15:00 | Outlook on special topics, Q&A, the Bro Center of Expertise |
You will find here slides, pointers to more documentation and other resources related to each topic we cover today.
During this training we are going to show you around in your Bro installation. Most of this can be found in the documentation in our Quickstart Guide. Also, go ahead and explore the install directory, typically /usr/local/bro. Assuming this is your install directory you can go from there to /usr/local/bro/share/bro/policy to find more useful Bro scripts that are not loaded by default. The script included by default are found in /usr/local/bro/share/bro/base. Scripts not in base can be loaded via local.bro which is located in /usr/local/bro/share/bro/site. The logs produced by Bro have a default location /usr/local/bro/logs.
Documentation for all Bro frameworks is here.
This is a very broad topic but there are some helpful entry points on the Bro website.
The slides for this topic are here.
The slides for this topic are here.
We will also spend some time on problem solving.
Bro setups for networks with 100G are very difficult. This case study written by Vincent Stoffer, Aashish Sharma, and Jay Krous is a unique source of experience and practical Bro deployment and usage.
The Net Control Framework allows you to let Bro modify the behavior of your network. The documentation is here. Netcontrol is still work in progress, especially the documentation is not complete yet. The most recent development is in github.
The Bro Center of Expertise is a central point of contact for institutions funded by the National Science Foundation (NSF) that bundles the Bro Team’s expertise and offers it to NSF-supported sites seeking advice.
We are constantly working on imrpovements. If you want to help us AND are a NSF site please fill out this survey. All information given is treated as confidential. The purpose of it is to get an overview of what NSF site look like. In the long riun we hope to develop tools and processes that makes it easier to get ro into your Science DMZ.
© 2014 The Bro Project.