Advertisement
taosecurity

Troubleshooting EQL with Zeek Logs 02

Mar 18th, 2019
112
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.26 KB | None | 0 0
  1. so16@so16:~$ eql query -f conn.mod.json --format jsonl "any where id_orig_h == '192_168_4_57'"
  2. Traceback (most recent call last):
  3. File "/home/so16/.local/bin/eql", line 11, in <module>
  4. sys.exit(main())
  5. File "/home/so16/.local/lib/python2.7/site-packages/eql/main.py", line 90, in main
  6. parsed.func(parsed)
  7. File "/home/so16/.local/lib/python2.7/site-packages/eql/main.py", line 60, in query
  8. engine.stream_events(stream, finalize=False)
  9. File "/home/so16/.local/lib/python2.7/site-packages/eql/engines/native.py", line 1205, in stream_events
  10. for event in events:
  11. File "/home/so16/.local/lib/python2.7/site-packages/eql/utils.py", line 172, in stream_file_events
  12. for event in stream_events(handle, file_format=file_format):
  13. File "/home/so16/.local/lib/python2.7/site-packages/eql/utils.py", line 146, in stream_json_lines
  14. yield json.loads(line)
  15. File "/usr/lib/python2.7/json/__init__.py", line 339, in loads
  16. return _default_decoder.decode(s)
  17. File "/usr/lib/python2.7/json/decoder.py", line 364, in decode
  18. obj, end = self.raw_decode(s, idx=_w(s, 0).end())
  19. File "/usr/lib/python2.7/json/decoder.py", line 380, in raw_decode
  20. obj, end = self.scan_once(s, idx)
  21. ValueError: Expecting ',' delimiter: line 1 column 192 (char 191)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement