# Bro 1.4 release now available

**URL:** <https://community.zeek.org/t/bro-1-4-release-now-available/1412>\
**Category:** Zeek\
**Created:** [October 17, 2008, 6:47pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412 "2008-10-17T18:47:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [October 17, 2008, 6:47pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/1 "2008-10-17T18:47:01Z")

</div>

Bro release 1.4 is now available from:

&nbsp;&nbsp;ftp://bro-ids.org/bro-1.4.tar.gz

This release includes significant new functionality as well as numerous  
refinements and fixes, per the appended changelog entries.

Previous releases are available at [http://www.bro-ids.org/download.html](http://www.bro-ids.org/download.html) .  
We do not anticipate making any further changes to them.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Aashish\_Sharma](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@Aashish\_Sharma](https://community.zeek.org/u/Aashish_Sharma)\
**Post date:** [October 17, 2008, 10:30pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/2 "2008-10-17T22:30:09Z")

</div>

Congratulations for the new release. I was looking forward for this.

Reading changelog says brolite may be deprecated. I see current 1.4 release is missing ../etc/bro.rc, ../etc/bro.cfg and ../site/local.site.bro files amongst others even after running "make install-brolite".

Is there any other recommended way to start/stop/run bro ?

Thanks,  
Aashish

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [October 18, 2008, 6:33pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/3 "2008-10-18T18:33:48Z")

</div>

> Reading changelog says brolite may be deprecated. I see current  
> 1.4 release is missing ../etc/bro.rc, ../etc/bro.cfg and  
> ../site/local.site.bro files amongst others even after running  
> "make install-brolite".

Hmmm... We'll look into that to see if it's an easy fix to get these  
installed by "make install-brolite".

> Is there any other recommended way to start/stop/run bro ?

There's is nothigng which ships with 1.4 at this point but the  
"Cluster Shell" we are working on has a "standalone mode" which  
makes it suitable for normal, single-box installation as well. See

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[The ICSI Networking Group Blog: An Interactive Shell For Operating Bro Setups](http://blog.icir.org/2008/04/interactive-shell-for-operating-bro.html)

This will likely become the standard installation scheme at some  
point.

Robin

---

<div class="post-metadata">

**Author:** ![Randolph\_Reitz](https://avatars.discourse-cdn.com/v4/letter/r/bb73d2/32.png) [@Randolph\_Reitz](https://community.zeek.org/u/Randolph_Reitz)\
**Post date:** [October 19, 2008, 1:06am UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/4 "2008-10-19T01:06:50Z")

</div>

> > Reading changelog says brolite may be deprecated. I see current  
> > 1.4 release is missing ../etc/bro.rc, ../etc/bro.cfg and  
> > ../site/local.site.bro files amongst others even after running  
> > "make install-brolite".
> 
> Hmmm... We'll look into that to see if it's an easy fix to get these  
> installed by "make install-brolite".
> 
> > Is there any other recommended way to start/stop/run bro ?
> 
> There's is nothigng which ships with 1.4 at this point but the  
> "Cluster Shell" we are working on has a "standalone mode" which  
> makes it suitable for normal, single-box installation as well. See
> 
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[The ICSI Networking Group Blog: An Interactive Shell For Operating Bro Setups](http://blog.icir.org/2008/04/interactive-shell-for-operating-bro.html)
> 
> This will likely become the standard installation scheme at some  
> point.

I have been using the "cluster shell" with BRO 1.4. I recently needed to hook in a process I want to start when BRO starts. I happily modified etc/bro.rc-hooks.sh, but this doesn't work. It seems that the cluster shell does not use etc/bro.rc for BRO startup and shutdown.

Does the cluster shell have a mechanism (Er, hook) for starting an external process?

Thanks,  
Randy

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [October 20, 2008, 4:46pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/5 "2008-10-20T16:46:31Z")

</div>

> etc/bro.rc-hooks.sh, but this doesn't work. It seems that the cluster  
> shell does not use etc/bro.rc for BRO startup and shutdown.

That's right. If the cron job is set up as described in the  
documentation, it will take care of restarting the cluster when the  
system starts up.

Adding a bro.rc-like script which starts/stops the cluster directly  
shouldn't be too hard though.

> Does the cluster shell have a mechanism (Er, hook) for starting an external  
> process?

No, it hasn't but that would be an easy extension as well. What  
exactly would you need? Just the capability to run an arbitrary  
script whenever the cluster start/stop commands are performed? (And  
if so, on any node's start/stop?)

Robin

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [January 12, 2009, 7:10pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/6 "2009-01-12T19:10:58Z")

</div>

It took me a bit to get back to this but there's now a patch for 1.4  
at [http://tracker.icir.org/bro/ticket/51](http://tracker.icir.org/bro/ticket/51) which I hope puts things  
back into place for "make install-brolite". I would appreciate it if  
somebody using BroLite could give it a try and let me know whether  
this indeed fixes it. (Please add any feedback directly to the  
tracker item).

Thanks,

Robin

P.S.: Please note that install-brolite remains deprecated and won't  
see any further updates. This is just to avoid breaking existing  
installations unnecessarily.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/bro-1-4-release-now-available/1412/7 "2022-05-06T15:38:42Z")

</div>


