# analyzer

**URL:** <https://community.zeek.org/t/analyzer/959>\
**Category:** Zeek\
**Created:** [May 3, 2006, 12:40pm UTC](https://community.zeek.org/t/analyzer/959 "2006-05-03T12:40:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bsila\_amine](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@bsila\_amine](https://community.zeek.org/u/bsila_amine)\
**Post date:** [May 3, 2006, 12:40pm UTC](https://community.zeek.org/t/analyzer/959/1 "2006-05-03T12:40:54Z")

</div>

Hi  
can any one please tell me the procedure to add a new  
protocol analyzer.  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Thanks

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [May 3, 2006, 4:01pm UTC](https://community.zeek.org/t/analyzer/959/2 "2006-05-03T16:01:52Z")

</div>

The best way to see how an analyzer works is to take a look at one  
of the more simple existing analyzers. For a TCP protocol, the  
finger analyzer is a good starting point (it's in Finger.{h,cc}; you  
can ignore anything related to trace rewriting). For UDP the NTP  
analyzer makes a good example.

Note that in the near future the analyzer interface will change, as  
we're working on a more general analyzer architecture (which is,  
e.g., able to analyze protocols independent of their well-know  
ports). It will be easy to convert analyzers to the new interface  
though.

Which protocol do you want to add?

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/analyzer/959/3 "2022-05-06T15:37:51Z")

</div>


