Intel alerts not showing up in the notice log

Hi Mike,

Thanks for the response. I’m still not seeing the Intel.log entries show up in my notice.log. I confirmed I have the @load policy/frameworks/intel/do_notice and @load frameworks/intel/seen in my local.bro file and the ‘T’ switch set on my DAT file entries. I’m not sure what to try next.

Any recommendations?

I assume you’ve also redef’d Intel::read_files as well.

How are you testing it? If you’re running standalone against a small pcap, I believe Bro may finish processing traffic before it finishes loading the Intel data. (Can anyone confirm or deny that?)

-Dop