# Bro traffic logging

**URL:** <https://community.zeek.org/t/bro-traffic-logging/986>\
**Category:** Zeek\
**Created:** [June 29, 2006, 8:17am UTC](https://community.zeek.org/t/bro-traffic-logging/986 "2006-06-29T08:17:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lee\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/c6cbf5/32.png) [@Lee\_Sheng](https://community.zeek.org/u/Lee_Sheng)\
**Post date:** [June 29, 2006, 8:17am UTC](https://community.zeek.org/t/bro-traffic-logging/986/1 "2006-06-29T08:17:05Z")

</div>

Is there a way when bro logs the suspicious traffics  
in pcap format but with separated files. Currently bro  
is logging it into the same files and that's hard to  
tell which is which. Is there any workaround or I'm  
overlooking because I'm just wondering how it can be  
done by logging different suscipicious traffics in  
different files.

Many thanks.

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [July 1, 2006, 5:36pm UTC](https://community.zeek.org/t/bro-traffic-logging/986/2 "2006-07-01T17:36:31Z")

</div>

There's no out-of-the-box solution for this but Bro provides the  
functions dump\_packet(pkt: pcap\_packet, file\_name: string) and  
get\_current\_packet() which can be used to achieve this. However, due  
to the packets being passed to the script-layer this with is most  
suitable for capturing a few selected packets, not a large bunch of  
them.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/bro-traffic-logging/986/3 "2022-05-06T15:37:54Z")

</div>


