# Bro not producing a notice.log

**URL:** <https://community.zeek.org/t/bro-not-producing-a-notice-log/4097>\
**Category:** Zeek\
**Created:** [April 7, 2016, 10:46pm UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097 "2016-04-07T22:46:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pawel](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@Pawel](https://community.zeek.org/u/Pawel)\
**Post date:** [April 7, 2016, 10:46pm UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/1 "2016-04-07T22:46:53Z")

</div>

I have a Bro cluster setup in the AWS cloud, currently just with one node. My problem is that Bro is not producing the notice.log, it should just log successful SSH logins but it doesn’t. I have tried SSH and FTP bruteforcing the worker node and exceeding the limit of failed connections, again no notice.log. I can see the detect-bruteforcing.bro scripts loaded in the loaded\_scripts.log. I am pretty new to Bro, so I am not sure what I am doing wrong.

Regards,

---

<div class="post-metadata">

**Author:** ![dopheide](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@dopheide](https://community.zeek.org/u/dopheide)\
**Post date:** [April 7, 2016, 11:04pm UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/2 "2016-04-07T23:04:39Z")

</div>

I want to say that’s likely because AWS disables promiscuous mode so getting Bro to work requires some additional tricks. Can anyone verify?

---

<div class="post-metadata">

**Author:** ![Jeff\_Geiger](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@Jeff\_Geiger](https://community.zeek.org/u/Jeff_Geiger)\
**Post date:** [April 8, 2016, 2:04am UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/3 "2016-04-08T02:04:04Z")

</div>

I don't know if anything has changed in the last few years, but I know it  
used to be the case that you could not put an AWS interface into  
promiscuous mode. To get around this, you had to use a tool like  
daemonlogger to dump packets from the external interface to a tap, tun, or  
bridge interface and monitor that. For larger scale implementations, you  
can use openvpn internally to route all the traffic back to your sensor. I  
set up a PoC doing similar with Snort a few years back. (  
[https://github.com/jeffgeiger/CloudSnort](https://github.com/jeffgeiger/CloudSnort)) Hopefully that helps, if this is  
still the case.

Best,

Jeff Geiger

---

<div class="post-metadata">

**Author:** ![Pawel](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@Pawel](https://community.zeek.org/u/Pawel)\
**Post date:** [April 8, 2016, 8:34am UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/4 "2016-04-08T08:34:45Z")

</div>

Jeff Geiger \<jeff.geiger \<at\> gmail.com\> writes:

> I don't know if anything has changed in the last few years, but I know it

used to be the case that you could not put an AWS interface into promiscuous  
mode. To get around this, you had to use a tool like daemonlogger to dump  
packets from the external interface to a tap, tun, or bridge interface and  
monitor that. For larger scale implementations, you can use openvpn  
internally to route all the traffic back to your sensor. I set up a PoC  
doing similar with Snort a few years back.  
([GitHub - jeffgeiger/CloudSnort: Bridge traffic over openvpn to a Snort sensor](https://github.com/jeffgeiger/CloudSnort)) Hopefully that helps, if this is  
still the case.

> Best,
> 
> Jeff Geiger
> 
> On Thu, Apr 7, 2016 at 6:04 PM, Mike Dopheide \<dopheide \<at\> gmail.com\>

wrote:I want to say that's likely because AWS disables promiscuous mode so  
getting Bro to work requires some additional tricks. Can anyone verify?

> I have a Bro cluster setup in the AWS cloud, currently just with one node.

My problem is that Bro is not producing the notice.log, it should just log  
successful SSH logins but it doesn't. I have tried SSH and FTP bruteforcing  
the worker node and exceeding the limit of failed connections, again no  
notice.log. I can see the detect-bruteforcing.bro scripts loaded in the  
loaded\_scripts.log. I am pretty new to Bro, so I am not sure what I am doing  
wrong.

> Regards,
> 
> \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
> Bro mailing listbro \<at\>

bro-ids.orghttp://mailman.ICSI.Berkeley.EDU/mailman/listinfo/bro

> \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_  
> Bro mailing list  
> bro \<at\> bro-ids.org  
> [mailman.icsi.berkeley.edu Mailing Lists](http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/bro)

So lets say I bridge an interface and start to monitor br0 instead of eth0,  
the br0 interface will not be in promiscuous mode and will allow to produce  
the notice.log? I am asking because you said you have done it few years ago,  
therefore wondering whether anything has changed in AWS.

I still can't understand it why is it not producing the notice.log. I have  
all the other logs (conn, http, ssl, x509 etc) and they are working fine. I  
am not sure how Bro exactly works but if there is more than 30 rejected FTP  
requests in the conn.log why doesn't it raise a notice if that's what the  
FTP-bruteforce is looking for.

Regards

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [April 8, 2016, 11:57am UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/5 "2016-04-08T11:57:33Z")

</div>

Are you running Bro on the machine that is running the ssh and ftp server?

Your logs are likely broken, but you haven't looked closely enough at them. Just because a log exists doesn't mean bro is seeing both sides of the connection.

[https://www.bro.org/documentation/faq.html#why-isn-t-bro-producing-the-logs-i-expect-a-note-about-checksums](https://www.bro.org/documentation/faq.html#why-isn-t-bro-producing-the-logs-i-expect-a-note-about-checksums)

---

<div class="post-metadata">

**Author:** ![Pawel](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@Pawel](https://community.zeek.org/u/Pawel)\
**Post date:** [April 9, 2016, 2:56pm UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/6 "2016-04-09T14:56:04Z")

</div>

That worked perfectly, thanks !!

However, now I am seeing a lot of possible\_split\_routing and  
data\_before\_established.  
Any ideas?

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/bro-not-producing-a-notice-log/4097/7 "2022-05-06T15:43:34Z")

</div>


