-
Notifications
You must be signed in to change notification settings - Fork 70
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fixup some minor changes in the ldap.log
- Loading branch information
Matti Bispham
committed
Nov 24, 2023
1 parent
e4d2125
commit 186f173
Showing
1 changed file
with
5 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -23,15 +23,15 @@ information. This is a quick overview of how the protocol works: | |
server by providing credentials. | ||
|
||
Queries: Clients search for entries in the LDAP directory using LDAP | ||
queries, which consist of a base DN, a scope (such as one level or the | ||
entire subtree), and a filter to match entries. Queries are read only. | ||
queries, which consist of a base Distinguished Name(DN), a scope (such | ||
as one level or the entire subtree), and a filter to match entries. Queries | ||
are read only. | ||
|
||
Operations: Clients with the correct privileges can perform a variety of | ||
operations; in addition to search, they can add, delete or modify. | ||
|
||
Data Format: LDAP data entries are formatted as records consisting of a | ||
distinguished name (DN) and a set of attributes. Each attribute has a name | ||
and one or more values. | ||
DN and a set of attributes. Each attribute has a name and one or more values. | ||
|
||
The LDAP analyzer outputs two LDAP related logs. :file:`ldap.log` contains | ||
details about the LDAP session except those related to searches. | ||
|
@@ -49,7 +49,7 @@ An example of an :file:`ldap.log`. | |
.. code-block:: console | ||
[email protected]:~ zeek -C LogAscii::use_json=T LDAP::default_log_search_attributes=T -r ldap-simpleauth.pcap | ||
[email protected]:~ jq . ldap_search.log | ||
[email protected]:~ jq . ldap.log | ||
:: | ||
|
||
|