You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If a user only wants to log Connection objects that have at least one analyzer, and ignore everything else, they should be able to.
For example, if someone wants to write an analyzer that filters for DNS traffic that contains domains ending in .io, they should be able to configure Gourmet to only log Connections that meet this filter, and ignore/drop everything else.
To implement this:
Create a new config.yml option called capture_mode with three options: minimal, normal, and payloads.
If minimal is set, only log connections that have met one or filters for the loaded analyzers
If normal is set, log all connections objects and any analyzer results (default, current mode)
If verbose is set, log all connection objects, a base64 dump of the connection payload, and any analyzer results
The text was updated successfully, but these errors were encountered:
If a user only wants to log Connection objects that have at least one analyzer, and ignore everything else, they should be able to.
For example, if someone wants to write an analyzer that filters for DNS traffic that contains domains ending in
.io
, they should be able to configure Gourmet to only log Connections that meet this filter, and ignore/drop everything else.To implement this:
capture_mode
with three options: minimal, normal, and payloads.The text was updated successfully, but these errors were encountered: