# about packet's load

**URL:** <https://community.zeek.org/t/about-packets-load/319>\
**Category:** Zeek\
**Created:** [December 24, 2002, 1:07pm UTC](https://community.zeek.org/t/about-packets-load/319 "2002-12-24T13:07:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaofu\_Wang](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Shaofu\_Wang](https://community.zeek.org/u/Shaofu_Wang)\
**Post date:** [December 24, 2002, 1:07pm UTC](https://community.zeek.org/t/about-packets-load/319/1 "2002-12-24T13:07:45Z")

</div>

Two hour to the great moment!  
Best wish!

> Ah - the term you're looking for is "payload". You can get this using  
> the "packet\_contents" event handler, or using the new signature engine  
> (for which Robin Sommer has contributed a new chapter for the Bro  
> manual, which will be included in the next development release).

void FragReassembler::AddFragment(const struct ip\* ip, const u\_char\* pkt,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;uint32 frag\_field)  
&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;......  
&nbsp;&nbsp;// Remove header.  
&nbsp;&nbsp;pkt += hdr\_len;  
&nbsp;&nbsp;len -= hdr\_len;  
&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;+ printf("%s,/n",(char \*) pkt);//change  
&nbsp;&nbsp;  
&nbsp;&nbsp;NewBlock(network\_time, offset, len, pkt);  
&nbsp;&nbsp;}  
I make the aboving change to print the payload of telnet , but it does not work!

Ciao  
Cloud

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/about-packets-load/319/2 "2022-05-06T15:36:39Z")

</div>


