# Bro script derived off of the referrer

**URL:** <https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564>\
**Category:** Zeek\
**Created:** [April 21, 2015, 2:13pm UTC](https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564 "2015-04-21T14:13:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brian\_Chilton](https://avatars.discourse-cdn.com/v4/letter/b/3be4f8/32.png) [@Brian\_Chilton](https://community.zeek.org/u/Brian_Chilton)\
**Post date:** [April 21, 2015, 2:13pm UTC](https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564/1 "2015-04-21T14:13:29Z")

</div>

All,

I am attempting to write a script that will key off of when the referrer is empty. The problem with that right now is that when I do this I have to use c$http$referrer == “-” which it does not like as an actual value. Is there another way to do this? I tried escaping it with a \ but that didn’t seem to work either. Any assistance you and provide would be great.

also, does anyone know where I can get some more info on the input framework?

Thanks,

BC

---

<div class="post-metadata">

**Author:** ![Oehlert\_Samuel](https://avatars.discourse-cdn.com/v4/letter/o/43a26b/32.png) [@Oehlert\_Samuel](https://community.zeek.org/u/Oehlert_Samuel)\
**Post date:** [April 21, 2015, 4:27pm UTC](https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564/2 "2015-04-21T16:27:00Z")

</div>

To check a field to see if it’s empty, you would use c$http?$referrer

As for input framework stuff:

[https://www.bro.org/sphinx-git/scripts/base/frameworks/input/main.bro.html](https://www.bro.org/sphinx-git/scripts/base/frameworks/input/main.bro.html) (this is for version 2.3)  
[http://blog.bro.org/2012/06/upcoming-loading-data-into-bro-with.html](http://blog.bro.org/2012/06/upcoming-loading-data-into-bro-with.html) (this blog post is a little older, but I _think_ still accurate)

-Sam

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [April 21, 2015, 5:44pm UTC](https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564/3 "2015-04-21T17:44:03Z")

</div>

Be sure to use the correct HTTP event, too. You don’t want to check for the referer before Bro has had a chance to add it to the connection object.

-AK

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [April 21, 2015, 6:27pm UTC](https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564/4 "2015-04-21T18:27:15Z")

</div>

There also is [https://www.bro.org/sphinx/frameworks/input.html](https://www.bro.org/sphinx/frameworks/input.html), which is  
probably the best starting point.

Johanna

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/bro-script-derived-off-of-the-referrer/3564/5 "2022-05-06T15:42:36Z")

</div>


