module_version: 1.0
var:
- name: paths
default:
- /var/log/bro/current/socks.log
os.linux:
- /var/log/bro/current/socks.log
os.darwin:
- /usr/local/var/logs/current/socks.log
- name: tags
default: [zeek.socks]
- name: internal_networks
default: [ private ]
ingest_pipeline: ingest/pipeline.yml
input: config/socks.yml