# about event handle

**URL:** <https://community.zeek.org/t/about-event-handle/284>\
**Category:** Zeek\
**Created:** [September 6, 2002, 1:15pm UTC](https://community.zeek.org/t/about-event-handle/284 "2002-09-06T13:15:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaofu\_Wang](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Shaofu\_Wang](https://community.zeek.org/u/Shaofu_Wang)\
**Post date:** [September 6, 2002, 1:15pm UTC](https://community.zeek.org/t/about-event-handle/284/1 "2002-09-06T13:15:42Z")

</div>

> \> in main(...):add some code like  
> \> Func \* wsf;  
> \> wsf=internal\_func("wsf");  
> \>  
> \> in bro.init:add a line as  
> \> global wsf: event (msg: string);  
> \> in login.bro: add a event as  
> \> event wsf (msg: string)  
> \> {  
> \> print msg;  
> \> }  
> \> And when I invoke bro : ./bro -i eth0 login.bro , bro does not work ,

with

> \> the error information :  
> \> lin1: internal error: internal variable wsf missing  
> \> Aborted .  
> \> Did I get the right way of creating and using event handle?
> 
> That's the correct way. Perhaps you're running into search-path problems,  
> in which the old version of bro.init is being found rather than the new  
> version you created. (Not the problem, of course, if you edited bro.init  
> in place rather than creating a new one.) The way to debug this is to  
> check the access time on the modified bro.init using "ls -lu" in order  
> to see whether it's indeed being read in. If it is, the next thing to  
> do is to introduce a syntax error in the definition of wsf to see whether  
> the line is indeed being parsed.

Thanks for your help.🙂  
The access time on the modified bro.init before running bro is the same to the time after running bro. What shoul I do to make the bro read the bro.init?

Have a nice day  
Ciao  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Cloud

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/about-event-handle/284/2 "2022-05-06T15:36:35Z")

</div>


