Document toolboxDocument toolbox

ids.bro

Introduction

The tags beginning with ids.bro identify events generated by Zeek Network Security Monitor.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as ids.bro. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Bro IDS (now Zeek Network Security Monitor)

ids.bro.captureloss

ids.bro.captureloss

ids.bro.communication

ids.bro.communication

ids.bro.conn

ids.bro.conn

ids.bro.dce_rpc

ids.bro.dce_rpc

ids.bro.dhcp

ids.bro.dhcp

ids.bro.dns

ids.bro.dns

ids.bro.dpd

ids.bro.dpd

ids.bro.files

ids.bro.files

ids.bro.ftp

ids.bro.ftp

ids.bro.http

ids.bro.http

ids.bro.kerberos

ids.bro.kerberos

ids.bro.knownhosts

ids.bro.knownhosts

ids.bro.knownservices

ids.bro.knownservices

ids.bro.notice

ids.bro.notice

ids.bro.ntlm

ids.bro.ntlm

ids.bro.ntp

ids.bro.ntp

ids.bro.packet_filter

ids.bro.packet_filter

ids.bro.pe

ids.bro.pe

ids.bro.rdp

ids.bro.rdp

ids.bro.reporter

ids.bro.reporter

ids.bro.smb_files

ids.bro.smb_files

ids.bro.smb_mapping

ids.bro.smb_mapping

ids.bro.snmp

ids.bro.snmp

ids.bro.software

ids.bro.software

ids.bro.ssh

ids.bro.ssh

ids.bro.ssl

ids.bro.ssl

ids.bro.stats

ids.bro.stats

ids.bro.weird

ids.bro.weird

ids.bro.x509

ids.bro.x509

For more information, read more About Devo tags.