Skip to content
This repository was archived by the owner on Apr 16, 2021. It is now read-only.
This repository was archived by the owner on Apr 16, 2021. It is now read-only.

securityonion-bro-scripts: update extract.bro for Bro 2.4 #754

@dougburks

Description

@dougburks

https://www.bro.org/download/NEWS.bro.html

"File analysis
Removed fa_file record’s mime_type and mime_types fields. The event file_sniff has been added which provides the same information. The mime_type field of Files::Info also still has this info.
The earliest point that new mime type information is available is in the file_sniff event which comes after the file_new and file_over_new_connection events. Scripts which inspected mime type info within those events will need to be adapted. (Note: for users that worked w/ versions of Bro from git, for a while there was also an event called file_mime_type which is now replaced with the file_sniff event)."

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions