bro files - network drive

Izik Birka <Izik.Birka@hot.net.il> writes:

Why when I only search file in network drive all the files in the
network drive are written to files.log ?

I'm assuming you mean over SMB? More data than just file transfers is
logged because it can be useful for incident response.

How can I detect a real file transfer ?

Take a look at the total_bytes and seen_bytes fields.

  --Vlad

hi
YES , over smb
my problem is when I searching files on file server all the files are written to files.log (include total_bytes and seen_bytes data)
and because of that I can't distinguish between search on file server and copy files from the file server

any suggestion ?

thanks