Open ckreibich opened 3 years ago
Establishing the connection state early has the benefit that code grabbing/logging the connection info sees the ID prior to the connection's state expiration.
@JustinAzoff, fyi!
yep.. and if you want a good test to ensure that this works. run it with https://github.com/corelight/zeek-long-connections and see if you get the community id stuff in the conn_long log.
Establishing the connection state early has the benefit that code grabbing/logging the connection info sees the ID prior to the connection's state expiration.
@JustinAzoff, fyi!