Skip to content
Discussion options

You must be logged in to vote

Configuring file extraction doesn't change which files are seen by Zeek and recorded in files.log, only which files are extracted to disk, scanned, and potentially preserved for later analysis. Configuring this feature doesn't change files.log at all, only if further actions are taken on the files (like scanning them with ClamAV, capa, YARA) after they are detected.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@H-Dynamite
Comment options

@mmguero
Comment options

Answer selected by mmguero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
bug Something isn't working
2 participants
Converted from issue

This discussion was converted from issue #649 on April 21, 2025 12:49.