Capture Loss when reading pcap with Zeek/Bro

0

I wanted to create logs with Zeek (Bro) from a pcap file. I read it with the -r option like bro -r my.pcap local Now I have the problem that the logs are created but with extremly much capture loss (about 20-70%). Why does this happen? Is the capture loss already in the pcap or is it a problem with Bro? What do I need to do to get no/much less capture loss?

bihemi

Posted 2019-10-09T10:12:02.410

Reputation: 1

No answers