Re: [Bro-Dev] Organizing plugins (Re: [JIRA] (BIT-1222) topic/robin/reader-writer-plugins)

2014-08-05 Thread Robin Sommer
reorg them broadly by functionality). Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev mailing list bro-dev@bro.org http://mailman.icsi.berkeley.edu/mailman

Re: [Bro-Dev] Organizing plugins (Re: [JIRA] (BIT-1222) topic/robin/reader-writer-plugins)

2014-08-05 Thread Robin Sommer
into external code? -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev mailing list bro-dev@bro.org http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev

[Bro-Dev] Organizing plugins (Re: [JIRA] (BIT-1222) topic/robin/reader-writer-plugins)

2014-08-04 Thread Robin Sommer
(Taking this to the mailing list for discussion.) On Mon, Aug 04, 2014 at 12:40 -0500, you wrote: I think that script and any tests (assuming the plugin test infrastructure is in place?) need to move into the plugin. Agreed in general. But there are two more general questions going in here I

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten for speed and to not depend on gawk

2014-08-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1215: - Assignee: Robin Sommer (was: Daniel Thayer) bro-cut should be rewritten for speed

[Bro-Dev] [JIRA] (BIT-1223) Merge topic/johanna/dhcp-log

2014-08-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1223?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1223: - Assignee: Robin Sommer Merge topic/johanna/dhcp-log

[Bro-Dev] [JIRA] (BIT-1223) Merge topic/johanna/dhcp-log

2014-08-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1223?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1223: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Merge topic/johanna

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten for speed and to not depend on gawk

2014-08-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1215: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) bro-cut should

[Bro-Dev] [JIRA] (BIT-1222) topic/robin/reader-writer-plugins

2014-07-31 Thread Robin Sommer (JIRA)
Robin Sommer created BIT-1222: - Summary: topic/robin/reader-writer-plugins Key: BIT-1222 URL: https://bro-tracker.atlassian.net/browse/BIT-1222 Project: Bro Issue Tracker Issue Type: Improvement

[Bro-Dev] [JIRA] (BIT-1220) topic/robin/dynamic-plugins-2.3

2014-07-30 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1220?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=17302#comment-17302 ] Robin Sommer commented on BIT-1220: --- Yeah, at a high level (we now have a plugin

[Bro-Dev] [JIRA] (BIT-1220) topic/robin/dynamic-plugins-2.3

2014-07-23 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1220?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1220: -- Status: Merge Request (was: Open) topic/robin/dynamic-plugins-2.3

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten for speed and to not depend on gawk

2014-07-22 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1215: -- Status: Open (was: Merge Request) bro-cut should be rewritten for speed and to not depend on gawk

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten for speed and to not depend on gawk

2014-07-22 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1215: - Assignee: Daniel Thayer (was: Robin Sommer) bro-cut should be rewritten for speed

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten for speed and to not depend on gawk

2014-07-22 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=17200#comment-17200 ] Robin Sommer commented on BIT-1215: --- I noticed a regression compared to the awk-version

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten for speed and to not depend on gawk

2014-07-20 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1215: - Assignee: Robin Sommer bro-cut should be rewritten for speed and to not depend on gawk

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten in C for speed and to not depend on gawk

2014-07-10 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=17105#comment-17105 ] Robin Sommer commented on BIT-1215: --- I haven't looked at the code yet but if there's hard

Re: [Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten in C for speed and to not depend on gawk

2014-07-10 Thread Robin Sommer
I haven't looked at the code yet but if there's hard line length limit in there, that's a problem. bro-cut shouldn't care how long lines are. ___ bro-dev mailing list bro-dev@bro.org http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev

[Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten in C for speed and to not depend on gawk

2014-07-10 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1215?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=17108#comment-17108 ] Robin Sommer commented on BIT-1215: --- Yes. Maybe a bit less than 2x, exponential grows

Re: [Bro-Dev] [JIRA] (BIT-1215) bro-cut should be rewritten in C for speed and to not depend on gawk

2014-07-10 Thread Robin Sommer
On Thu, Jul 10, 2014 at 17:27 -0500, you wrote: I think start with 1M and realloc 2x as needed is the way to go after all. Yes. Maybe a bit less than 2x, exponential grows quickly. :) I think the only thing to do would be to add an absolute max line length of 64M or something to handle

[Bro-Dev] [JIRA] (BIT-1213) broccoli/bindings/broccoli-python not building correctly

2014-07-09 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1213?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1213: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) broccoli/bindings

[Bro-Dev] [JIRA] (BIT-1213) broccoli/bindings/broccoli-python not building correctly

2014-07-08 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1213?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1213: - Assignee: Robin Sommer broccoli/bindings/broccoli-python not building correctly

Re: [Bro-Dev] Documenting Weirds

2014-07-01 Thread Robin Sommer
:) This is not a huge issue, and could probably be solved with a few wrappers covering common cases (and we have some of that already, like the WeirdConn() etc.; could extend that a bit more). Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666

[Bro-Dev] [JIRA] (BIT-1213) broccoli/bindings/broccoli-python not building correctly

2014-06-30 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1213?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1213: -- Status: Merge Request (was: Open) broccoli/bindings/broccoli-python not building correctly

[Bro-Dev] [JIRA] (BIT-1211) Bro fails to compile with DataSeries support

2014-06-28 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1211?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1211: -- Status: Closed (was: Merge Request) Bro fails to compile with DataSeries support

[Bro-Dev] [JIRA] (BIT-1209) bro-cut needs tests

2014-06-27 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1209?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1209: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) bro-cut needs tests

Re: [Bro-Dev] Documenting Weirds

2014-06-27 Thread Robin Sommer
linked to docs. In either case it would be nice if the scheme unified reporting weirds from core and script land. Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev

[Bro-Dev] [JIRA] (BIT-1211) Bro fails to compile with DataSeries support

2014-06-26 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1211?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16901#comment-16901 ] Robin Sommer commented on BIT-1211: --- At first I thought we'd need ifdef's to support old

[Bro-Dev] Time for C++11?

2014-06-23 Thread Robin Sommer
? Robin [1] While we are at that, I suggest we also (re-)up the cmake version. Probably hard to find a C++11 tool chain with a many-years-old cmake. -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin

Re: [Bro-Dev] Time for C++11?

2014-06-23 Thread Robin Sommer
-compiler-support-shootout-visual-studio-gcc-clang-intel/ Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev mailing list bro-dev@bro.org http

Re: [Bro-Dev] Time for C++11?

2014-06-23 Thread Robin Sommer
that might remain a matter of taste. Personally, for example, I usually go for the source even if a project offers RPMs. So I'm not sure I would relax requirements just because we have more/better binaries. Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510

Re: [Bro-Dev] Time for C++11?

2014-06-23 Thread Robin Sommer
to the list? Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev mailing list bro-dev@bro.org http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev

Re: [Bro-Dev] Looking on feedback on PACF/reaction framework

2014-06-20 Thread Robin Sommer
with the simple model for his work though. Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev mailing list bro-dev@bro.org http://mailman.icsi.berkeley.edu/mailman/listinfo

Re: [Bro-Dev] 2.3 ready?

2014-06-13 Thread Robin Sommer
On Wed, Jun 11, 2014 at 14:30 -0700, I wrote: I would propose to get the release out on Monday otherwise. Alright, sounds like everybody's happy, so let's get it out. Jon is going to be our Release Master. Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL

[Bro-Dev] [JIRA] (BIT-1202) Segfault with double redef of table[subnet] of subnet

2014-06-11 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1202?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1202: -- Resolution: Merged Status: Closed (was: Open) Segfault with double redef of table[subnet

[Bro-Dev] [JIRA] (BIT-1195) SSL: subject overflow in issuer_subject

2014-06-11 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1195?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1195: -- Status: Closed (was: Reopened) SSL: subject overflow in issuer_subject

[Bro-Dev] [JIRA] (BIT-1203) Fixing SMTP state tracking in topic/robin/smtp-fix

2014-06-10 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1203?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16802#comment-16802 ] Robin Sommer commented on BIT-1203: --- I would like a double check on this fix. It introduces

[Bro-Dev] [JIRA] (BIT-1203) Fixing SMTP state tracking in topic/robin/smtp-fix

2014-06-10 Thread Robin Sommer (JIRA)
Robin Sommer created BIT-1203: - Summary: Fixing SMTP state tracking in topic/robin/smtp-fix Key: BIT-1203 URL: https://bro-tracker.atlassian.net/browse/BIT-1203 Project: Bro Issue Tracker Issue

[Bro-Dev] [JIRA] (BIT-1203) Fixing SMTP state tracking in topic/robin/smtp-fix

2014-06-10 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1203?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1203: -- Status: Merge Request (was: Open) Fixing SMTP state tracking in topic/robin/smtp-fix

[Bro-Dev] [JIRA] (BIT-1201) merge topic/bernhard/ssl-new-events

2014-06-06 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1201?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1201: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) merge topic/bernhard

[Bro-Dev] [JIRA] (BIT-1140) Bloomfilter hashing problem

2014-06-05 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1140?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1140: - Assignee: Robin Sommer (was: Matthias Vallentin) Bloomfilter hashing problem

[Bro-Dev] [JIRA] (BIT-1140) Bloomfilter hashing problem

2014-06-05 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1140?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1140: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Bloomfilter hashing

[Bro-Dev] [JIRA] (BIT-1195) SSL: subject overflow in issuer_subject

2014-06-03 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1195?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1195: -- Status: Reopened (was: Closed) SSL: subject overflow in issuer_subject

[Bro-Dev] [JIRA] (BIT-1195) SSL: subject overflow in issuer_subject

2014-06-02 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1195?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1195: - Assignee: Robin Sommer (was: Bernhard Amann) SSL: subject overflow in issuer_subject

Re: [Bro-Dev] [Auto] Merge Status

2014-06-02 Thread Robin Sommer
-- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL* Fax +1 (510) 666-2956 * www.icir.org/robin ___ bro-dev mailing list bro-dev@bro.org http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev

[Bro-Dev] [JIRA] (BIT-1186) Improve cluster configuration documentation

2014-05-16 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1186?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1186: - Assignee: Robin Sommer (was: Daniel Thayer) Improve cluster configuration documentation

Re: [Bro-Dev] [Bro-Commits] [git/bro] fastpath: Fix a doc build warning (d230eed)

2014-05-16 Thread Robin Sommer
address, or an empty string in the case of an error. function normalize_mac(a: string): string ___ bro-commits mailing list bro-comm...@bro.org http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-commits -- Robin Sommer * Phone +1 (510

Re: [Bro-Dev] [Bro-Commits] [git/broctl] fastpath: Rename the broctl option pfringdnafirstappinstance (1b78449)

2014-05-16 Thread Robin Sommer
process running on that DNA cluster. Bro must be linked with PF_RING's libpcap wrapper and PFRINGClusterID must be non-zero for this option to work.), Just checking: The description still says dna, is that intentional? Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org

[Bro-Dev] [JIRA] (BIT-1190) Even more SSL fixes

2014-05-16 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1190?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1190: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Even more SSL fixes

[Bro-Dev] [JIRA] (BIT-845) PF_RING+DNA

2014-05-16 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-845?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-845: - Resolution: Merged Status: Closed (was: Open) PF_RING+DNA --- Key

[Bro-Dev] [JIRA] (BIT-1177) SumStats dynamic updates do not work in cluster mode

2014-05-15 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1177?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16500#comment-16500 ] Robin Sommer commented on BIT-1177: --- Ping. SumStats dynamic updates do not work in cluster

[Bro-Dev] [JIRA] (BIT-1129) RADIUS Protocol Analyzer

2014-05-15 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1129?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-1129: - Assignee: Robin Sommer (was: Vlad Grigorescu) RADIUS Protocol Analyzer

[Bro-Dev] [JIRA] (BIT-1129) RADIUS Protocol Analyzer

2014-05-15 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1129?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1129: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) RADIUS Protocol

[Bro-Dev] Merging updates

2014-05-08 Thread Robin Sommer
we generally merges and generally commits to master: http://www.bro.org/development/howtos/process.html#committing-to-master http://www.bro.org/development/howtos/process.html#merging-a-topic-branch Robin -- Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org ICSI/LBNL

[Bro-Dev] [JIRA] (BIT-348) Reassembler integer overflow issues. Data not delivered after 2GB

2014-05-08 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-348?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16400#comment-16400 ] Robin Sommer commented on BIT-348: -- thanks for tracking this done, sounds reasonable. I looked

[Bro-Dev] [JIRA] (BIT-1185) topic/dnthayer/broctld-work

2014-05-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1185?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1185: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) topic/dnthayer/broctld

[Bro-Dev] [JIRA] (BIT-1189) merge topic/bernhard/ec-curve

2014-05-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1189?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1189: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) merge topic/bernhard

[Bro-Dev] [JIRA] (BIT-1150) X509 updates

2014-04-25 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1150?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1150: -- Status: Merge Request (was: Reopened) X509 updates Key: BIT-1150

[Bro-Dev] [JIRA] (BIT-1141) Investigate further improvements to file analysis performance

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16222#comment-16222 ] Robin Sommer commented on BIT-1141: --- {quote} How ugly would it be (or would it even work

[Bro-Dev] [JIRA] (BIT-1141) Investigate further improvements to file analysis performance

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16223#comment-16223 ] Robin Sommer commented on BIT-1141: --- Here are the performance improvements I'm seeing: {code

[Bro-Dev] [JIRA] (BIT-1141) Investigate further improvements to file analysis performance

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16221#comment-16221 ] Robin Sommer edited comment on BIT-1141 at 4/24/14 6:15 PM: Two

[Bro-Dev] [JIRA] (BIT-1141) Investigate further improvements to file analysis performance

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1141?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16221#comment-16221 ] Robin Sommer edited comment on BIT-1141 at 4/24/14 6:15 PM: Two

[Bro-Dev] [JIRA] (BIT-1185) topic/dnthayer/broctld-work

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1185?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1185: -- Status: Open (was: Merge Request) topic/dnthayer/broctld-work

[Bro-Dev] [JIRA] (BIT-1168) Add Java version to software framework

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1168: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Add Java version

[Bro-Dev] [JIRA] (BIT-1156) DNS analyzer parses TXT records imcompletely

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1156?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1156: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) DNS analyzer parses

[Bro-Dev] [JIRA] (BIT-1187) topic/jsiwek/remove-val-attribs

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1187?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1187: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) topic/jsiwek/remove

[Bro-Dev] [JIRA] (BIT-1178) SSL/TLS analyzer does not abort early enough on non-ssl connections

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1178?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1178: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) SSL/TLS analyzer does

[Bro-Dev] [JIRA] (BIT-348) Reassembler integer overflow issues. Data not delivered after 2GB

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-348?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16226#comment-16226 ] Robin Sommer edited comment on BIT-348 at 4/24/14 10:25 PM: Alright

[Bro-Dev] [JIRA] (BIT-348) Reassembler integer overflow issues. Data not delivered after 2GB

2014-04-24 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-348?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16227#comment-16227 ] Robin Sommer commented on BIT-348: -- I did some more testing on a large trace, and I am seeing

Re: [Bro-Dev] [JIRA] (BIT-1185) topic/dnthayer/broctld-work

2014-04-23 Thread Robin Sommer
Just doing a hash of broctl.cfg itself wouldn't work very well, because there are various ways that the broctl config can change: I don't think I'm too concerned about these, as generally they all seem rare enough that an additional warning wouldn't hurt much. I have another idea though:

[Bro-Dev] [JIRA] (BIT-1185) topic/dnthayer/broctld-work

2014-04-23 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1185?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16210#comment-16210 ] Robin Sommer commented on BIT-1185: --- I don't think I'm too concerned about

[Bro-Dev] [JIRA] (BIT-348) Reassembler integer overflow issues. Data not delivered after 2GB

2014-04-22 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-348?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer reassigned BIT-348: Assignee: Robin Sommer (was: Jon Siwek) Reassembler integer overflow issues. Data not delivered

[Bro-Dev] [JIRA] (BIT-1184) topic/jsiwek/odesc-escaping

2014-04-22 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1184?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1184: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) topic/jsiwek/odesc

[Bro-Dev] [JIRA] (BIT-1177) SumStats dynamic updates do not work in cluster mode

2014-04-21 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1177?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1177: -- Assignee: Seth Hall (was: Bernhard Amann) SumStats dynamic updates do not work in cluster mode

[Bro-Dev] [JIRA] (BIT-1183) topic/jsiwek/ascii-log-memleak-fix

2014-04-18 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1183?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16203#comment-16203 ] Robin Sommer commented on BIT-1183: --- Excellent catch! topic/jsiwek/ascii-log-memleak

[Bro-Dev] [JIRA] (BIT-1183) topic/jsiwek/ascii-log-memleak-fix

2014-04-17 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1183?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1183: -- Status: Closed (was: Merge Request) topic/jsiwek/ascii-log-memleak-fix

[Bro-Dev] [JIRA] (BIT-1179) HTTP messages missing in files.log

2014-04-10 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1179?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16112#comment-16112 ] Robin Sommer commented on BIT-1179: --- Agree, if that's indeed the reason, it's nothing to fix

[Bro-Dev] [JIRA] (BIT-1181) Input-framework errors should be fatal (or Notice_Alarm) instead of silent reporter::error failures

2014-04-09 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1181?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16107#comment-16107 ] Robin Sommer commented on BIT-1181: --- We could in principle add an input_framework_error

[Bro-Dev] [JIRA] (BIT-1142) SNMP Analysis

2014-04-08 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1142?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1142: -- Status: Open (was: Merge Request) SNMP Analysis - Key: BIT-1142

[Bro-Dev] [JIRA] (BIT-1181) Input-framework errors should be fatal (or Notice_Alarm) instead of silent reporter::error failures

2014-04-07 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1181?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16104#comment-16104 ] Robin Sommer commented on BIT-1181: --- I don't think we should turn this into a fatal error

[Bro-Dev] [JIRA] (BIT-1177) SumStats dynamic updates do not work in cluster mode

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1177?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1177: -- Assignee: Bernhard Amann SumStats dynamic updates do not work in cluster mode

[Bro-Dev] [JIRA] (BIT-1171) misc/app-stats/main.bro broken for a few sites

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1171?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16014#comment-16014 ] Robin Sommer commented on BIT-1171: --- We'll remove (comment out) the ones which don't work

[Bro-Dev] [JIRA] (BIT-1176) Using an undefined function in a when statement causes a segfault

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1176?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1176: -- Fix Version/s: (was: 2.3) 2.4 Using an undefined function in a when statement

[Bro-Dev] [JIRA] (BIT-1162) Sumstat measurements stop working on clusters with single slow nodes

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1162?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1162: -- Resolution: Fixed Status: Closed (was: Open) BIT-1170 fixed the immediate problem, although

[Bro-Dev] [JIRA] (BIT-1171) misc/app-stats/main.bro broken for a few sites

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1171?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1171: -- Assignee: Seth Hall misc/app-stats/main.bro broken for a few sites

[Bro-Dev] [JIRA] (BIT-1142) SNMP Analysis

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1142?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1142: -- Status: Merge Request (was: Open) SNMP Analysis - Key: BIT-1142

[Bro-Dev] [JIRA] (BIT-1137) Investigate sumstats / scan detector performance

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1137?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1137: -- Resolution: Fixed Status: Closed (was: Open) As there no clear task here., let's close

[Bro-Dev] [JIRA] (BIT-1150) X509 updates

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1150?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1150: -- Assignee: Bernhard Amann (was: Robin Sommer) X509 updates Key: BIT

[Bro-Dev] [JIRA] (BIT-845) PF_RING+DNA

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-845?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16017#comment-16017 ] Robin Sommer edited comment on BIT-845 at 4/4/14 1:52 PM: -- Still needs

[Bro-Dev] [JIRA] (BIT-1142) SNMP Analysis

2014-04-04 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1142?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1142: -- Assignee: Robin Sommer (was: Seth Hall) SNMP Analysis - Key: BIT

[Bro-Dev] [JIRA] (BIT-1175) topic/jsiwek/bif-loader-scripts

2014-04-03 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1175?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1175: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) topic/jsiwek/bif

[Bro-Dev] [JIRA] (BIT-1174) topic/jsiwek/coverity

2014-04-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1174?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1174: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) topic/jsiwek/coverity

[Bro-Dev] [JIRA] (BIT-1163) Logging framework text (ascii) writer writes sets as table[...]

2014-04-01 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1163?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1163: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Logging framework text

[Bro-Dev] [JIRA] (BIT-1150) X509 updates

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1150?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=16000#comment-16000 ] Robin Sommer commented on BIT-1150: --- Please give me some text for CHANGES and NEWS

[Bro-Dev] [JIRA] (BIT-1169) topic/jsiwek/parse-only

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1169?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1169: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) topic/jsiwek/parse

[Bro-Dev] [JIRA] (BIT-1143) Investigate replacing libmagic w/ signatures for file identificaiton

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1143?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1143: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Investigate replacing

[Bro-Dev] [JIRA] (BIT-1150) X509 updates

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1150?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1150: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) X509 updates

[Bro-Dev] [JIRA] (BIT-1150) X509 updates

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1150?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1150: -- Status: Reopened (was: Closed) X509 updates Key: BIT-1150

[Bro-Dev] [JIRA] (BIT-1168) Add Java version to software framework

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1168: -- Status: Merge Request (was: Open) Add Java version to software framework

[Bro-Dev] [JIRA] (BIT-1160) Update cluster documentation

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1160?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1160: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) Update cluster

[Bro-Dev] [JIRA] (BIT-1159) type checking inconsistencies

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1159?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1159: -- Resolution: Merged (was: Fixed) Status: Closed (was: Merge Request) type checking

[Bro-Dev] [JIRA] (BIT-1172) Add uid field to the signatures log stream

2014-03-31 Thread Robin Sommer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1172?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robin Sommer updated BIT-1172: -- Status: Merge Request (was: Open) Add uid field to the signatures log stream

<    3   4   5   6   7   8   9   10   11   >