zeek
Here are 60 public repositories matching this topic...
Currently, at least the values from XML tags tcpsequence and ipidsequence are not kept. The schema should be updated to store them.
See also #636.
Repro is in Brim v0.14.0.
There's a link to the ZQL docs from the pull-down menu via Help > Query Syntax Docs that works as I'd expect, in that it opens up the docs in my browser. However, I recently noticed (per the attached video) that there's also a "Syntax docs" option available in the vertical "..." menu to the right of the search bar. When clicked, I find I can't move the window, no
-
Updated
May 14, 2020 - Jupyter Notebook
-
Updated
Jul 28, 2020 - Python
-
Updated
May 9, 2020 - Zeek
-
Updated
Mar 17, 2020 - Zeek
-
Updated
Aug 17, 2020 - Python
-
Updated
Aug 16, 2020 - Zeek
-
Updated
Jul 10, 2020 - Zeek
-
Updated
Jul 21, 2020 - PHP
-
Updated
Sep 15, 2019 - JavaScript
-
Updated
Apr 12, 2020
-
Updated
Jun 14, 2020 - Zeek
-
Updated
Mar 4, 2020 - Zeek
-
Updated
Mar 19, 2020 - Zeek
-
Updated
Jun 14, 2020 - Shell
-
Updated
Aug 11, 2020 - Zeek
-
Updated
Jun 30, 2020 - Zeek
-
Updated
May 8, 2020 - Zeek
-
Updated
Aug 18, 2019 - SaltStack
-
Updated
Aug 29, 2019 - Go
-
Updated
Feb 27, 2020
Improve this page
Add a description, image, and links to the zeek topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the zeek topic, visit your repo's landing page and select "manage topics."


zeek-cut currently has ability to output "header blocks" in prefix to records. It would be helpful if there was an option that output a simple header row that contained only the corresponding field names, the target format supporting essentially CSV ready output.
Convoluted example of how we're achieving/using today with (for example) the Miller tool to postprocess: