Unified2¶| Namespace: | Unified2 |
|---|---|
| Imports: | base/utils/dir.bro, base/utils/paths.bro |
| Source File: | /scripts/base/files/unified2/main.bro |
Unified2::classification_config: string &redef |
The classification.config file you would like to use for your alerts. |
Unified2::gen_msg: string &redef |
The gen-msg.map file you would like to use for your alerts. |
Unified2::sid_msg: string &redef |
The sid-msg.map file you would like to use for your alerts. |
Unified2::watch_dir: string &redef |
Directory to watch for Unified2 records. |
Unified2::watch_file: string &redef |
File to watch for Unified2 files. |
Unified2::alert: event |
Reconstructed “alert” which combines related events and packets. |
Unified2::log_unified2: event |
The event for accessing logged records. |
Unified2::classification_config¶| Type: | string |
|---|---|
| Attributes: | &redef |
| Default: | "" |
The classification.config file you would like to use for your alerts.
Unified2::gen_msg¶| Type: | string |
|---|---|
| Attributes: | &redef |
| Default: | "" |
The gen-msg.map file you would like to use for your alerts.
Unified2::sid_msg¶| Type: | string |
|---|---|
| Attributes: | &redef |
| Default: | "" |
The sid-msg.map file you would like to use for your alerts.
Unified2::Info¶| Type: |
|
|---|---|
| Attributes: |
Unified2::alert¶| Type: | event (f: fa_file, ev: Unified2::IDSEvent, pkt: Unified2::Packet) |
|---|
Reconstructed “alert” which combines related events and packets.
Unified2::log_unified2¶| Type: | event (rec: Unified2::Info) |
|---|
The event for accessing logged records.