How does one leverage this framework to write scripts?
Start with the video:
Then review these exercises:
These are both from the Bro Exchange 2013.
It depends on what you want to do. The docs we have for it show you how to use it (to get an intel.log file). Is that all you're interested in? Loading data and finding things that hit?
Does the framework take care of updating the system on the fly if the input files change, or is a restart needed?
It updates on the fly. If you are running a cluster you only need to update the data on the manager too. It will auto distribute.