bro files - network drive

Izik Birka <> writes:

Why when I only search file in network drive all the files in the
network drive are written to files.log ?

I'm assuming you mean over SMB? More data than just file transfers is
logged because it can be useful for incident response.

How can I detect a real file transfer ?

Take a look at the total_bytes and seen_bytes fields.


YES , over smb
my problem is when I searching files on file server all the files are written to files.log (include total_bytes and seen_bytes data)
and because of that I can't distinguish between search on file server and copy files from the file server

any suggestion ?