> To: Kenneth Goldman <kgoldman@us.ibm.com>, <bro@bro.org> > Date: 05/22/2017 04:47 PM > Subject: Re: [Bro] does bro need root privilege? > > The BroControl documentation explains how to run as a normal user: > https://www.bro.org/sphinx/components/broctl/README.html#using- > brocontrol-as-an-unprivileged-user
The spool and logs directories are in my home directory, and I edited /etc/bro/broctl.cfg to point to them. They are rwx.
> From: Seth Hall <seth@corelight.com> > To: Kenneth Goldman <kgoldman@us.ibm.com> > Cc: bro <bro@bro.org> > Date: 05/31/2017 03:20 PM > Subject: Re: [Bro] Missing notice.log, have weird.log > > On Wed, May 31, 2017 at 2:31 PM, Kenneth Goldman <kgoldman@us.ibm.com> wrote: > > The quick starter refers to a notice.log file. It's not being created. > > Logs in Bro are created when they are written to. It's like that none > of the scripts you have loaded are generating notices.
Should it generate notices "out of the box"? I have not done any customization.
notice/main.bro says this, which I read to mean ignore nothing.