# \#718: Log protocol type for notices

**URL:** <https://community.zeek.org/t/718-log-protocol-type-for-notices/2177>\
**Category:** Development\
**Tags:** development\
**Created:** [January 4, 2012, 7:11pm UTC](https://community.zeek.org/t/718-log-protocol-type-for-notices/2177 "2012-01-04T19:11:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Martin\_Holste](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@Martin\_Holste](https://community.zeek.org/u/Martin_Holste)\
**Post date:** [January 4, 2012, 7:11pm UTC](https://community.zeek.org/t/718-log-protocol-type-for-notices/2177/1 "2012-01-04T19:11:27Z")

</div>

It would be very helpful if all of the logs started with the  
connection tuple to make parsing easier.

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [January 5, 2012, 5:00pm UTC](https://community.zeek.org/t/718-log-protocol-type-for-notices/2177/2 "2012-01-05T17:00:50Z")

</div>

We're trying to avoid relying on the order of fields. The recommended  
way is to parse the header and then index columns by their names.  
While using columns directly would be easier of course, it makes it  
hard to change a log's content in the future.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/718-log-protocol-type-for-notices/2177/3 "2022-05-06T15:40:06Z")

</div>


