Skip to content
Discussion options

You must be logged in to vote

It's normal for Zeek to log the ICMP type as source port and ICMP code as destination port. For more information, please see https://docs.zeek.org/en/current/scripts/base/protocols/conn/main.zeek.html:

ICMP “ports” are to be interpreted as the source port meaning the ICMP message type and the destination port being the ICMP message code.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@Carlos-mb
Comment options

@dougburks
Comment options

Answer selected by Carlos-mb
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants