Re: [Zeek-Dev] [EXT] Re: connection $history - 'g' for gap

2019-04-10 Thread McMahon, Kevin J
Agreed, but I think there is broader use for knowing, from the conn.log, that there were gaps. I think the 'g' character would address that. I've always loved the history field and have found numerous uses for it over the years. Kevin -Original Message- From: v...@icir.org On Behalf

Re: [Zeek-Dev] [EXT] Re: connection $history - 'g' for gap

2019-04-10 Thread Vern Paxson
> That could get very messy in the real world. How about start of first gap,= > length of first gap, total number of gaps? I think if the goal is to know whether DPD failed due to content gaps, much better than trying to infer that from a set of gap information would be for dpd.log to include "n

Re: [Zeek-Dev] [EXT] Re: connection $history - 'g' for gap

2019-04-10 Thread McMahon, Kevin J
That could get very messy in the real world. How about start of first gap, length of first gap, total number of gaps? Sent with BlackBerry Work (www.blackberry.com) From: anthony kasza mailto:anthony.ka...@gmail.com>> Date: Wednesday, Apr 10, 2019, 12:18 AM To: Jim Mellander mailto:jmellan...@