1
2
mirror of https://github.com/vimagick/dockerfiles synced 2024-06-25 16:28:40 +00:00
dockerfiles/bro
2015-06-22 16:11:00 +08:00
..
docker-compose.yml update 2015-06-22 15:56:44 +08:00
Dockerfile update 2015-06-22 16:11:00 +08:00
README.md update 2015-06-22 15:56:44 +08:00

Bro is a powerful system that on top of the functionality it provides out of the box, also offers the flexibility to customize analysis pretty much arbitrarily. We provide a range of documentation material ranging from introductory material to get you started, to full references of Bros various frameworks.

docker-compose.yml

bro:
  image: vimagick/bro
  command: bro -i eth0
  volumes:
    - ./logs:/opt/bro/logs
  net: host

up and running

$ cd ~/fig/bro/

$ docker-compose up -d

$ docker exec -it bro_bro_1 bash
>>> tail -n +1 -f http.log | bro-cut -d ts user_agent
>>> exit