# BPF Filter per log file or framework such as x509, SSL

**URL:** <https://community.zeek.org/t/bpf-filter-per-log-file-or-framework-such-as-x509-ssl/3834>\
**Category:** Zeek\
**Created:** [September 18, 2015, 8:28am UTC](https://community.zeek.org/t/bpf-filter-per-log-file-or-framework-such-as-x509-ssl/3834 "2015-09-18T08:28:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ludwig\_Goon](https://avatars.discourse-cdn.com/v4/letter/l/46a35a/32.png) [@Ludwig\_Goon](https://community.zeek.org/u/Ludwig_Goon)\
**Post date:** [September 18, 2015, 8:28am UTC](https://community.zeek.org/t/bpf-filter-per-log-file-or-framework-such-as-x509-ssl/3834/1 "2015-09-18T08:28:53Z")

</div>

when activating the x509.log or bro script in local.bro, can I configure a BPF filter to only affect x509 framework? For example I only want to have events that the dst\_host is our DMZ subnet. Can I configure that in the x509.bro file/framework or some other bro configuration file? If so is this a local variable called subnet or something?

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [September 18, 2015, 5:15pm UTC](https://community.zeek.org/t/bpf-filter-per-log-file-or-framework-such-as-x509-ssl/3834/2 "2015-09-18T17:15:57Z")

</div>

Just to repeat my answer from the bug tracker:

you can add bpf filters with the syntax described in  
[https://www.bro.org/sphinx/scripts/base/frameworks/packet-filter/main.bro.html](https://www.bro.org/sphinx/scripts/base/frameworks/packet-filter/main.bro.html)

The thread at  
[http://comments.gmane.org/gmane.comp.security.detection.bro/4759](http://comments.gmane.org/gmane.comp.security.detection.bro/4759) also has  
a few examples. There is no easy way to tell Bro to just allow traffic  
containing x509 certificates - you have to build the filter yourself, only  
allowing the hosts and services that have traffic containing x509  
certificates. If using broctl, typically you would add the filter commands  
to local.bro or to a script that you load from local.bro – it is  
discouraged to edit any scripts in base/ or policy/ yourself.

Do you need anything else, or does that perhaps fulfill your requirements?

Johanna

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/bpf-filter-per-log-file-or-framework-such-as-x509-ssl/3834/3 "2022-05-06T15:43:05Z")

</div>


