# bro 2.5 . How to get meta fields on intel.log

**URL:** <https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688>\
**Category:** Zeek\
**Created:** [February 23, 2017, 12:18pm UTC](https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688 "2017-02-23T12:18:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Giedrius\_Ramas](https://avatars.discourse-cdn.com/v4/letter/g/59ef9b/32.png) [@Giedrius\_Ramas](https://community.zeek.org/u/Giedrius_Ramas)\
**Post date:** [February 23, 2017, 12:18pm UTC](https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688/1 "2017-02-23T12:18:08Z")

</div>

Hi ,

How can we get working those bro extensions for Bro 2.4 on Bro 2.5  
Currently I get errors:

error in /opt/bro/share/bro/base/frameworks/intel/./main.bro, line 155: already defined (Intel::extend\_match)  
internal warning in /opt/bro/share/bro/my\_scripts/intel-ext/./scripts/main.bro, line 20: Duplicate identifier documentation: Intel::extend\_match  
proxy scripts failed.  
error in /opt/bro/share/bro/base/frameworks/intel/./main.bro, line 155: already defined (Intel::extend\_match)  
internal warning in /opt/bro/share/bro/my\_scripts/intel-ext/./scripts/main.bro, line 20: Duplicate identifier documentation: Intel::extend\_match  
ids-nksc004-eth1-1 scripts failed.  
error in /opt/bro/share/bro/base/frameworks/intel/./main.bro, line 155: already defined (Intel::extend\_match)  
internal warning in /opt/bro/share/bro/my\_scripts/intel-ext/./scripts/main.bro, line 20: Duplicate identifier documentation: Intel::extend\_match

Our intel data have following format :

#fields indicator indicator\_type meta.desc meta.cif\_confidence meta.source

And we need to have these meta’s: meta.desc, meta.cif\_confidence, meta.source on bro.intel log as previously had with bro extensions for Bro 2.4 found on [https://github.com/sethhall/intel-ext](https://github.com/sethhall/intel-ext)

.

Or question is how to get meta fields on bro intel.log.?

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [February 23, 2017, 1:12pm UTC](https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688/2 "2017-02-23T13:12:38Z")

</div>

Hi,

> How can we get working those bro extensions for Bro 2.4 on Bro 2.5  
> Currently I get errors:  
> ...  
> line 20: Duplicate identifier documentation: Intel::extend\_match

the intel framework has been reworked for 2.5 and includes a similar  
extension mechanism (a hook instead of an event). The following blog  
entry goes into details:  
[http://blog.bro.org/2016/12/the-intelligence-framework-update.html](http://blog.bro.org/2016/12/the-intelligence-framework-update.html)

> Or question is how to get meta fields on bro intel.log.?

You can use the extension mechanisms included but keep in mind that each  
hit might be associated with multiple indicators and each indicator  
might be associated with multiple meta data records.

Jan

---

<div class="post-metadata">

**Author:** ![Giedrius\_Ramas](https://avatars.discourse-cdn.com/v4/letter/g/59ef9b/32.png) [@Giedrius\_Ramas](https://community.zeek.org/u/Giedrius_Ramas)\
**Post date:** [February 23, 2017, 2:34pm UTC](https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688/3 "2017-02-23T14:34:55Z")

</div>

Thanks, Jan  
Got it working .

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [February 23, 2017, 2:40pm UTC](https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688/4 "2017-02-23T14:40:52Z")

</div>

Sorry about the confusion. I'll put a note on that repository that the feature is now built into Bro and point to Jan's blog post.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/bro-2-5-how-to-get-meta-fields-on-intel-log/4688/5 "2022-05-06T15:44:40Z")

</div>


