# Development

**URL:** https://community.zeek.org/c/development/7.md?page=1

[Latest](https://community.zeek.org/latest.md) · [Categories](https://community.zeek.org/categories.md) · [Tags](https://community.zeek.org/tags.md)

**Page:** 2

---

## [Renaming the Packet::l2\_checksummed and Packet::l3\_checksummed variables](https://community.zeek.org/t/renaming-the-packet-l2-checksummed-and-packet-l3-checksummed-variables/6570)

<div class="topic-metadata">

**Author:** [@Tim\_Wojtulewicz](https://community.zeek.org/u/Tim_Wojtulewicz)\
**Replies:** 1\
**Last updated:** [July 1, 2022, 4:25pm UTC](https://community.zeek.org/t/renaming-the-packet-l2-checksummed-and-packet-l3-checksummed-variables/6570 "2022-07-01T16:25:03Z")

</div>

Is anyone out there using the Packet::l2\_checksummed and Packet::l3\_checksummed variables? We discovered recently that those are improperly named for their intended uses, and need to rename them. It’d make it easier if I…

---

## [Zeek benchmarks](https://community.zeek.org/t/zeek-benchmarks/6429)

<div class="topic-metadata">

**Author:** [@DW\_via\_zeek-dev](https://community.zeek.org/u/DW_via_zeek-dev)\
**Replies:** 4\
**Last updated:** [December 15, 2021, 6:18pm UTC](https://community.zeek.org/t/zeek-benchmarks/6429 "2021-12-15T18:18:16Z")

</div>

Hi everyone, I have a Zeek plugin (Zeek-Dpdk) that provides native DPDK support for Zeek as a packet source. I ran some benchmarks and wanted to validate the results with the community. The benchmarking scenario is as …

---

## [I have a question about “Use multiple ZEEK to process traffic”](https://community.zeek.org/t/i-have-a-question-about-use-multiple-zeek-to-process-traffic/6431)

<div class="topic-metadata">

**Author:** [@Bran\_Lu](https://community.zeek.org/u/Bran_Lu)\
**Replies:** 0\
**Last updated:** [December 15, 2021, 12:48am UTC](https://community.zeek.org/t/i-have-a-question-about-use-multiple-zeek-to-process-traffic/6431 "2021-12-15T00:48:31Z")

</div>

Hi zeek-dev In my program, I started ZEEK (named zeek1) to analyze a large file (the analysis will last for a long time), and started another ZEEK (named zeek2) to analyze the traffic of eth0 port. When I changed the co…

---

## [Possible memory leak in logger process?](https://community.zeek.org/t/possible-memory-leak-in-logger-process/6428)

<div class="topic-metadata">

**Author:** [@redbaron](https://community.zeek.org/u/redbaron)\
**Replies:** 4\
**Last updated:** [December 14, 2021, 5:38am UTC](https://community.zeek.org/t/possible-memory-leak-in-logger-process/6428 "2021-12-14T05:38:58Z")

</div>

Hi, We have a Zeek node that sees high volumes on working days. Due to our internal network configuration a lot of connections for our internal DNS servers are generated by certain endpoints (because our DNS does not re…

---

## [Zeek benchmarks validation](https://community.zeek.org/t/zeek-benchmarks-validation/6421)

<div class="topic-metadata">

**Author:** [@DW\_via\_zeek-dev](https://community.zeek.org/u/DW_via_zeek-dev)\
**Replies:** 0\
**Last updated:** [October 22, 2021, 4:44pm UTC](https://community.zeek.org/t/zeek-benchmarks-validation/6421 "2021-10-22T16:44:34Z")

</div>

Hi everyone, I have a Zeek plugin (Zeek-Dpdk) that provides native DPDK support for Zeek as a packet source. I ran some benchmarks and wanted to validate the results with the community. The benchmarking scenario is as …

---

## [Plugin did not instantiate](https://community.zeek.org/t/plugin-did-not-instantiate/6383)

<div class="topic-metadata">

**Author:** [@DW\_via\_zeek-dev](https://community.zeek.org/u/DW_via_zeek-dev)\
**Replies:** 0\
**Last updated:** [July 28, 2021, 5:55pm UTC](https://community.zeek.org/t/plugin-did-not-instantiate/6383 "2021-07-28T17:55:57Z")

</div>

Hi there, I'm trying to create a new protocol analyzer as a plugin but stumble to get it running. I run into following exception: /home/user/plugin/build///lib/plugin-Test.linux-x86\_64.so did not instantiate a plugin T…

---

## [Anomaly-based intrusion detection in Zeek](https://community.zeek.org/t/anomaly-based-intrusion-detection-in-zeek/6318)

<div class="topic-metadata">

**Author:** [@Zeya\_Umayya](https://community.zeek.org/u/Zeya_Umayya)\
**Replies:** 0\
**Last updated:** [March 19, 2021, 9:54am UTC](https://community.zeek.org/t/anomaly-based-intrusion-detection-in-zeek/6318 "2021-03-19T09:54:59Z")

</div>

Hi, as per the Zeek documentation- "Zeek is not a classic signature-based intrusion detection system (IDS); while it supports such standard functionality as well, Zeek’s scripting language facilitates a much broader sp…

---

## [netmap 2.0.0 vs. zeek 4.0.0](https://community.zeek.org/t/netmap-2-0-0-vs-zeek-4-0-0/6316)

<div class="topic-metadata">

**Author:** [@leres](https://community.zeek.org/u/leres)\
**Replies:** 4\
**Last updated:** [March 16, 2021, 10:04pm UTC](https://community.zeek.org/t/netmap-2-0-0-vs-zeek-4-0-0/6316 "2021-03-16T22:04:41Z")

</div>

I'm trying to update the FreeBSD zeek port for 4.0.0 and am having trouble getting netmap 2.0.0 to build which seems to assume that zeek will be installed in /usr/local when it is built: \[ 40%\] Building CXX object …

---

## [Proposed change to lambda semantics - shallow copying rather than references](https://community.zeek.org/t/proposed-change-to-lambda-semantics-shallow-copying-rather-than-references/6276)

<div class="topic-metadata">

**Author:** [@Vern](https://community.zeek.org/u/Vern)\
**Replies:** 14\
**Last updated:** [December 11, 2020, 6:47pm UTC](https://community.zeek.org/t/proposed-change-to-lambda-semantics-shallow-copying-rather-than-references/6276 "2020-12-11T18:47:18Z")

</div>

Hi Folks, For the script optimization/compilation work I’ve been doing, I’ve been looking into what it will take to compile lambdas (anonymous functions). Currently, these use “reference” semantics when referring to loc…

---

## [Platform support policy](https://community.zeek.org/t/platform-support-policy/6239)

<div class="topic-metadata">

**Author:** [@robin](https://community.zeek.org/u/robin)\
**Replies:** 14\
**Last updated:** [November 13, 2020, 12:44pm UTC](https://community.zeek.org/t/platform-support-policy/6239 "2020-11-13T12:44:08Z")

</div>

\[I had posted this on Slack in #development originally, copying here for visibility\] We now have the nice list of platforms that Zeek currently supports at: https://github.com/zeek/zeek/wiki/Zeek-Operating-System-Supp…

---

## [Documenting new Notice Types in Packages?](https://community.zeek.org/t/documenting-new-notice-types-in-packages/6254)

<div class="topic-metadata">

**Author:** [@Vlad\_Grigorescu](https://community.zeek.org/u/Vlad_Grigorescu)\
**Replies:** 2\
**Last updated:** [October 20, 2020, 2:13am UTC](https://community.zeek.org/t/documenting-new-notice-types-in-packages/6254 "2020-10-20T02:13:36Z")

</div>

Something I’d like to figure out is how to document new notice types in the package documentation. If I add a new notice type, e.g. redef enum Notice::Type += { IPv6 Router Advertisement packet seen with the Recursiv…

---

## [schools near marathahalli](https://community.zeek.org/t/schools-near-marathahalli/6251)

<div class="topic-metadata">

**Author:** [@foundationschoolindi](https://community.zeek.org/u/foundationschoolindi)\
**Replies:** 0\
**Last updated:** [October 15, 2020, 8:01am UTC](https://community.zeek.org/t/schools-near-marathahalli/6251 "2020-10-15T08:01:07Z")

</div>

The Foundation schools were established in 2009. The Gunjur branch has become one of the top CBSE schools in varthur, Gunjur, Whitefield and best school in Sarjapur Road areas in a short period of time. The schools follo…

---

## [CentOS7 SPEC File Broken](https://community.zeek.org/t/centos7-spec-file-broken/6249)

<div class="topic-metadata">

**Author:** [@DW\_via\_zeek-dev](https://community.zeek.org/u/DW_via_zeek-dev)\
**Replies:** 1\
**Last updated:** [October 14, 2020, 11:20am UTC](https://community.zeek.org/t/centos7-spec-file-broken/6249 "2020-10-14T11:20:33Z")

</div>

Hi, The recent zeek.spec files for CentOS7 are broken: %if 0%{?centos\_version} == 700 BuildRequires: llvm-toolset-7-cmake devtoolset-7-gcc-c++ devtoolset-7-elfutils devtoolset-7-binutils devtoolset-7-make devtoolset-7-…

---

## [LTS RPM MaxMind Support](https://community.zeek.org/t/lts-rpm-maxmind-support/6248)

<div class="topic-metadata">

**Author:** [@DW\_via\_zeek-dev](https://community.zeek.org/u/DW_via_zeek-dev)\
**Replies:** 1\
**Last updated:** [October 13, 2020, 7:53am UTC](https://community.zeek.org/t/lts-rpm-maxmind-support/6248 "2020-10-13T07:53:25Z")

</div>

Hi, Pardon the possibly dumb question: is there a reason for NOT building the LTS RPM with libmaxminddb support? Thank you.

---

## [Unit tests in plugins?](https://community.zeek.org/t/unit-tests-in-plugins/6223)

<div class="topic-metadata">

**Author:** [@seth](https://community.zeek.org/u/seth)\
**Replies:** 3\
**Last updated:** [September 10, 2020, 2:27pm UTC](https://community.zeek.org/t/unit-tests-in-plugins/6223 "2020-09-10T14:27:41Z")

</div>

Has anyone put any thought to how we could create and run unit tests in Zeek plugins? I don't think any work has been done on that yet, but I'd love to be able to create unit tests in plugins. thanks! .Seth

---

## [Cluster Controller Framework Thoughts](https://community.zeek.org/t/cluster-controller-framework-thoughts/6220)

<div class="topic-metadata">

**Author:** [@Vlad\_Grigorescu](https://community.zeek.org/u/Vlad_Grigorescu)\
**Replies:** 2\
**Last updated:** [September 8, 2020, 7:36pm UTC](https://community.zeek.org/t/cluster-controller-framework-thoughts/6220 "2020-09-08T19:36:04Z")

</div>

Rather lengthy post follows. In case people didn’t see it, much of this references this document: https://docs.google.com/document/d/1r0wXnihx4yESOpLJ87Wh2g1V-aHOFUkbgiFe8RHJpZo/edit The past couple of weeks, I upgraded…

---

## [Moving policy scripts into packages](https://community.zeek.org/t/moving-policy-scripts-into-packages/6215)

<div class="topic-metadata">

**Author:** [@robin](https://community.zeek.org/u/robin)\
**Replies:** 15\
**Last updated:** [September 3, 2020, 7:03am UTC](https://community.zeek.org/t/moving-policy-scripts-into-packages/6215 "2020-09-03T07:03:59Z")

</div>

Looking for some thoughts here. One of the items on the roadmap for 4.0 is moving scripts that currently live in policy/ over into Zeek packages. The goals here are to (1) facilitate maintaining & testing them indepen…

---

## [Discussion: the guidance we want to give to package authors on the tags they assign](https://community.zeek.org/t/discussion-the-guidance-we-want-to-give-to-package-authors-on-the-tags-they-assign/6213)

<div class="topic-metadata">

**Author:** [@Duffy\_OCraven](https://community.zeek.org/u/Duffy_OCraven)\
**Replies:** 5\
**Last updated:** [August 18, 2020, 6:59pm UTC](https://community.zeek.org/t/discussion-the-guidance-we-want-to-give-to-package-authors-on-the-tags-they-assign/6213 "2020-08-18T18:59:15Z")

</div>

I want to start a discussion here of the guidance we want to give to package authors on the tags they assign in zkg.meta, to ensure people have a chance to chime in, and we start-out with the benefit of multi-perspective…

---

## [Proposal: Make Zeek's debug logging thread-safe](https://community.zeek.org/t/proposal-make-zeeks-debug-logging-thread-safe/6177)

<div class="topic-metadata">

**Author:** [@Bob\_Murphy](https://community.zeek.org/u/Bob_Murphy)\
**Replies:** 12\
**Last updated:** [July 18, 2020, 8:48pm UTC](https://community.zeek.org/t/proposal-make-zeeks-debug-logging-thread-safe/6177 "2020-07-18T20:48:33Z")

</div>

Right now, if you try to use Zeek’s debug logging facilities in DebugLogger.h concurrently from multiple threads, the contents of debug.log can get mixed up and look like like “word salad”. I’ve been working on log writ…

---

## [Proposal: Improve Zeek's log-writing system with batch support and better status reporting](https://community.zeek.org/t/proposal-improve-zeeks-log-writing-system-with-batch-support-and-better-status-reporting/6178)

<div class="topic-metadata">

**Author:** [@Bob\_Murphy](https://community.zeek.org/u/Bob_Murphy)\
**Replies:** 5\
**Last updated:** [July 17, 2020, 9:54am UTC](https://community.zeek.org/t/proposal-improve-zeeks-log-writing-system-with-batch-support-and-better-status-reporting/6178 "2020-07-17T09:54:04Z")

</div>

Summary This proposal is aimed at solving two intertwined problems in Zeek’s log- writing system: Problem: Batch writing code duplication Some log writers need to send multiple log records at a time in “batches”. T…

---

## [Zeek Table Cluster distribution using broker ready for testing](https://community.zeek.org/t/zeek-table-cluster-distribution-using-broker-ready-for-testing/6176)

<div class="topic-metadata">

**Author:** [@johanna](https://community.zeek.org/u/johanna)\
**Replies:** 0\
**Last updated:** [July 9, 2020, 8:21pm UTC](https://community.zeek.org/t/zeek-table-cluster-distribution-using-broker-ready-for-testing/6176 "2020-07-09T20:21:44Z")

</div>

Hello everyone, If you followed last year’s Zeek Week, you might be aware that we have been working on a new way to more easily distribute Zeek Table content in a cluster setup. We now have a working prototype - and I w…

---

## [Email Zeek](https://community.zeek.org/t/email-zeek/6170)

<div class="topic-metadata">

**Author:** [@Petar\_Backovic](https://community.zeek.org/u/Petar_Backovic)\
**Replies:** 0\
**Last updated:** [July 5, 2020, 8:19am UTC](https://community.zeek.org/t/email-zeek/6170 "2020-07-05T08:19:33Z")

</div>

Respected devs, I installed Zeek and configure interface, email, private IP address, etc. I copied script for SSH password guessing from docs.zeekweb site and my listener on wlan0 works. When I failed to login on SSH …

---

## [Zeek Supervisor: designing client and log archival behavior](https://community.zeek.org/t/zeek-supervisor-designing-client-and-log-archival-behavior/6167)

<div class="topic-metadata">

**Author:** [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Replies:** 4\
**Last updated:** [July 2, 2020, 7:44am UTC](https://community.zeek.org/t/zeek-supervisor-designing-client-and-log-archival-behavior/6167 "2020-07-02T07:44:08Z")

</div>

Looking for feedback on the design/plan for these two Zeek Supervisor components: \* https://github.com/zeek/zeek/wiki/Zeek-Supervisor-Client \* https://github.com/zeek/zeek/wiki/Zeek-Supervisor-Log-Handling - Jon

---

## [Zeek Supervisor Command-Line Client](https://community.zeek.org/t/zeek-supervisor-command-line-client/6158)

<div class="topic-metadata">

**Author:** [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Replies:** 13\
**Last updated:** [July 1, 2020, 9:02am UTC](https://community.zeek.org/t/zeek-supervisor-command-line-client/6158 "2020-07-01T09:02:08Z")

</div>

Don't recall any basic "project infrastructure" discussions happening yet for the upcoming replacement/alternative for ZeekControl that we want to introduce in Zeek 3.2 (roadmap/design links found at \[1\]), so here's s…

---

## [Use zeek scripts only with the "manager" in a cluster configuration](https://community.zeek.org/t/use-zeek-scripts-only-with-the-manager-in-a-cluster-configuration/6146)

<div class="topic-metadata">

**Author:** [@Davide\_Robusto](https://community.zeek.org/u/Davide_Robusto)\
**Replies:** 2\
**Last updated:** [June 10, 2020, 5:20pm UTC](https://community.zeek.org/t/use-zeek-scripts-only-with-the-manager-in-a-cluster-configuration/6146 "2020-06-10T17:20:38Z")

</div>

Hi, I have abnormal behavior when I use the same script in two different configurations: Zeek single thread configuration Zeek configuration with four cores and four workers. By starting the script in question, in the…

---

## [Compiling Zeek-3.1.x using devtoolset-7 to generate a binary package for use in CentOS-7](https://community.zeek.org/t/compiling-zeek-3-1-x-using-devtoolset-7-to-generate-a-binary-package-for-use-in-centos-7/6126)

<div class="topic-metadata">

**Author:** [@redbaron](https://community.zeek.org/u/redbaron)\
**Replies:** 2\
**Last updated:** [May 26, 2020, 6:18am UTC](https://community.zeek.org/t/compiling-zeek-3-1-x-using-devtoolset-7-to-generate-a-binary-package-for-use-in-centos-7/6126 "2020-05-26T06:18:50Z")

</div>

Hi, We have been using Zeek-3.0.x RPM packages for CentOS-7 which are compiled using spec file derived from zeek src package and they worked well. Now we are considering upgrading to Zeek-3.1.x but that requires newer …

---

## [Next supervisor steps](https://community.zeek.org/t/next-supervisor-steps/6060)

<div class="topic-metadata">

**Author:** [@robin](https://community.zeek.org/u/robin)\
**Replies:** 0\
**Last updated:** [March 26, 2020, 8:42am UTC](https://community.zeek.org/t/next-supervisor-steps/6060 "2020-03-26T08:42:51Z")

</div>

Zeek 3.1 introduced a first, experimental version of the new supervisor framework that we expect to eventually replace ZeekControl as the primary mechanism to run Zeek clusters, both single- and multi-system. See the …

---

## [2.4.1 to 3.0.1](https://community.zeek.org/t/2-4-1-to-3-0-1/6008)

<div class="topic-metadata">

**Author:** [@Dk\_Jack](https://community.zeek.org/u/Dk_Jack)\
**Replies:** 2\
**Last updated:** [February 14, 2020, 5:48pm UTC](https://community.zeek.org/t/2-4-1-to-3-0-1/6008 "2020-02-14T17:48:11Z")

</div>

Hi, We have a (c++) plugin that we have been using with 2.4.1. We are trying to move to 3.0.x. Is there any documentation on api changes (deprecations) that we need to be concerned about? Our plugin is an analyzer de…

---

## [Wrapping up 3.1](https://community.zeek.org/t/wrapping-up-3-1/5993)

<div class="topic-metadata">

**Author:** [@robin](https://community.zeek.org/u/robin)\
**Replies:** 0\
**Last updated:** [February 4, 2020, 12:18pm UTC](https://community.zeek.org/t/wrapping-up-3-1/5993 "2020-02-04T12:18:39Z")

</div>

We're planing to wrap up Zeek 3.1 this week with code freeze on Friday and then a beta version out early next week. The 3.1.0 GitHub project shows the current state, please make sure we have tickets on there for every…

---

## [Question about IntrusivePtr and incomplete types](https://community.zeek.org/t/question-about-intrusiveptr-and-incomplete-types/5943)

<div class="topic-metadata">

**Author:** [@johanna](https://community.zeek.org/u/johanna)\
**Replies:** 4\
**Last updated:** [December 17, 2019, 3:28pm UTC](https://community.zeek.org/t/question-about-intrusiveptr-and-incomplete-types/5943 "2019-12-17T15:28:28Z")

</div>

Hi, I just tried to use our new IntrusivePtr type for the first time - and encountered a (for me) unexpected problem. In my specific case, I want to introduce a new member variable for TableVal. The type of it is: I…

[Previous page](https://community.zeek.org/c/development/7.md)

[Next page](https://community.zeek.org/c/development/7.md?page=2)
