# Bro HTTPS analyzer

**URL:** <https://community.zeek.org/t/bro-https-analyzer/4338>\
**Category:** Zeek\
**Created:** [September 16, 2016, 6:43am UTC](https://community.zeek.org/t/bro-https-analyzer/4338 "2016-09-16T06:43:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohan\_Dhawan](https://avatars.discourse-cdn.com/v4/letter/m/a87d85/32.png) [@Mohan\_Dhawan](https://community.zeek.org/u/Mohan_Dhawan)\
**Post date:** [September 16, 2016, 6:43am UTC](https://community.zeek.org/t/bro-https-analyzer/4338/1 "2016-09-16T06:43:06Z")

</div>

Dear All,

I wish to analyze HTTPS traffic with Bro and want to know what specific  
changes might need to be done to the existing HTTP analyzer framework.

Thanks for the help.

Regards,  
mohan

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [September 16, 2016, 8:58am UTC](https://community.zeek.org/t/bro-https-analyzer/4338/2 "2016-09-16T08:58:13Z")

</div>

This really depends on your HTTP traffic. Bro handles the majority of HTTP cleanly directly out of the box. Have you tried feeding Bro some same trace files to see what shows up in the http.log file?

-AK

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/bro-https-analyzer/4338/3 "2022-05-06T15:44:00Z")

</div>


