# Bro \<-\> Snort documentation

**URL:** <https://community.zeek.org/t/bro-snort-documentation/385>\
**Category:** Zeek\
**Created:** [July 11, 2003, 10:34pm UTC](https://community.zeek.org/t/bro-snort-documentation/385 "2003-07-11T22:34:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [July 11, 2003, 10:34pm UTC](https://community.zeek.org/t/bro-snort-documentation/385/1 "2003-07-11T22:34:26Z")

</div>

I sent this to Vern, but thought a wider audience might be interested,  
or have some answers.

Thanks Vern:

I'm planning on using the snort engine to extend KO (Kazaa  
Obliterator). It looks like I could use a policy script like this:

signature kazaa-seen {  
&nbsp;&nbsp;ip-proto == tcp  
&nbsp;&nbsp;dst-ip == whatever  
&nbsp;&nbsp;dst-port == whatever (or omitted, I guess)  
&nbsp;&nbsp;payload /.\*kazaa regular expression/  
&nbsp;&nbsp;eval function\_to\_execute\_when\_kazaa\_seen  
&nbsp;&nbsp;event "kazaa seen"  
}

The 'eval' & the 'event' are somewhat confusing. I presume that the  
'signature\_match' event is triggered with the string for action, but  
when is the 'eval' called (before the event, or after), and with what  
args? Presumably the connection information is available. I haven't  
seen any running examples of the signature event. Do you have some  
examples?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/bro-snort-documentation/385/2 "2022-05-06T15:36:47Z")

</div>


