Hi Izik,
in share/bro/policy/protocols/smb/main.smb
look for write_cmd_log =F, if you change it to T, it will start the printing.
good luck
B
Hi Izik,
in share/bro/policy/protocols/smb/main.smb
look for write_cmd_log =F, if you change it to T, it will start the printing.
good luck
B
As a small addendum; that log probably isn't very useful. It was mostly created to be used during development because it logs every single SMB cmd that is seen (and there are *lots* of SMB cmd messages sent around).
.Seth