# Broccoli Code Not Working : Not receiving any events

**URL:** <https://community.zeek.org/t/broccoli-code-not-working-not-receiving-any-events/4185>\
**Category:** Zeek\
**Created:** [June 3, 2016, 5:42am UTC](https://community.zeek.org/t/broccoli-code-not-working-not-receiving-any-events/4185 "2016-06-03T05:42:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sherine\_Davis\_Securi](https://avatars.discourse-cdn.com/v4/letter/s/d07c76/32.png) [@Sherine\_Davis\_Securi](https://community.zeek.org/u/Sherine_Davis_Securi)\
**Post date:** [June 3, 2016, 5:42am UTC](https://community.zeek.org/t/broccoli-code-not-working-not-receiving-any-events/4185/1 "2016-06-03T05:42:40Z")

</div>

Broccoli code :

#include \<sys/types.h\>  
#include \<sys/socket.h\>  
#include \<sys/wait.h\>  
#include \<sys/time.h\>  
#include \<stdio.h\>  
#include \<stdlib.h\>  
#include \<time.h\>  
#include \<errno.h\>  
#include \<string.h\>  
#include \<inttypes.h\>  
#include \<broccoli.h\>  
#include \<unistd.h\>  
#include \<stdbool.h\>  
#include \<string.h\>

#ifdef HAVE\_CONFIG\_H  
#include \<config.h\>  
#endif

char \*host\_default = “127.0.0.1”;  
char \*port\_default = “64646”;  
char \*host\_str;  
char \*port\_str;

// The variables that monitor the rate  
float tcp\_packet\_out = 0;  
float tcp\_packet\_in = 0;  
float udp\_packet\_in = 0;  
float udp\_packet\_out = 0;

uint64 seq;

static void  
usage(void)  
{  
printf(“cero\_traffic\n”);  
exit(0);  
}

// For every TCP\_PACKET event  
static void  
bro\_tcp\_packet(BroConn \*bc, void \*data, BroRecord \*conn, int \*is\_orig, BroString \*flags,int \*seq, int \*ack, int \*len, BroString \*payload)  
{

printf(“1\n\n”);  
if(is\_orig)  
{  
tcp\_packet\_in++;  
}  
else  
{  
tcp\_packet\_out++;  
}

conn = NULL;  
data = NULL;  
}

// For every UDP\_REQUEST event  
static void  
bro\_udp\_request(BroConn \*conn, void \*data)  
{  
printf(“2\n\n”);  
udp\_packet\_in++;

conn = NULL;  
data = NULL;  
}

// For every UDP\_REPLY event  
static void  
bro\_udp\_reply(BroConn \*conn, void \*data)  
{  
udp\_packet\_out++;

conn = NULL;  
data = NULL;  
}

// Main driver function  
// Mainly deals with creating and establishing the connection with Bro  
int  
main(int argc, char \*\*argv)  
{

printf(“Starting program”);  
BroConn \*bc;  
char hostname[512];  
int fd = -1;

bro\_init(NULL);

host\_str = host\_default;  
port\_str = port\_default;  
printf(“Marker1-success”);  
snprintf(hostname, 512, “%s:%s”, host\_str, port\_str);

if (! (bc = bro\_conn\_new\_str(hostname, BRO\_CFLAG\_RECONNECT)))  
{  
printf(“Could not get Bro connection handle.\n”);  
exit(-1);  
}

bro\_event\_registry\_add(bc, “tcp\_packet”, (BroEventFunc) bro\_tcp\_packet, NULL);  
/\* bro\_event\_registry\_add(bc, “udp\_request”, (BroEventFunc) bro\_udp\_request, NULL);  
bro\_event\_registry\_add(bc, “udp\_reply”, (BroEventFunc) bro\_udp\_reply, NULL);  
\*/

printf(“Marker2-success”);  
if (! bro\_conn\_connect(bc))  
{  
printf(“Could not connect to Bro at %s:%s.\n”, host\_str, port\_str);  
exit(-1);  
}

printf(“Marker3-success”);  
for(;😉  
{  
sleep(1);  
printf(“in\n”);  
bro\_event\_registry\_request(bc);  
bro\_conn\_process\_input(bc);

// printf(“tcp\_packet\_out : %f tcp\_packet\_in : %f udp\_packet\_in : %f udp\_packet\_out : %f \n”,tcp\_packet\_out,tcp\_packet\_in,udp\_packet\_in,udp\_packet\_out);  
}

/\* Disconnect from Bro and release state. \*/  
bro\_conn\_delete(bc);

return 0;  
}

Bro Code :

@load policy/frameworks/communication/listen

# Let’s make sure we use the same port no matter whether we use encryption or not:

redef Communication::listen\_port = 64646/tcp;

# Redef this to T if you want to use SSL.

redef Communication::listen\_ssl = F;

# Set the SSL certificates being used to something real if you are using encryption.

#redef ssl\_ca\_certificate = “/ca\_cert.pem”;  
#redef ssl\_private\_key = “/bro.pem”;

redef Communication::nodes += {  
[“cero\_traffic”] = [$host = 127.0.0.1, $connect=F, $ssl=F]  
};

global ct\_log = open\_log\_file(“cero\_traffic”);

event tcp\_packet(c: connection, is\_orig: bool, flags: string, seq: count, ack: count, len: count, payload: string)  
{  
if(is\_orig)  
print fmt(“TCP PACKET | CONN: %s:%s \> %s:%s |FLAG: %s |LEN: %s”,c$id$orig\_h,c$id$orig\_p,c$id$resp\_h,c$id$resp\_p,flags,len);  
else  
print fmt(“TCP PACKET | CONN: %s:%s \> %s:%s |FLAG: %s |LEN: %s”,c$id$resp\_h,c$id$resp\_p,c$id$orig\_h,c$id$orig\_p,flags,len);

}

#event udp\_request(u: connection)  
#{

# print fmt(“UDP PACKET | CONN: %s:%s \> %s:%s”,u$id$orig\_h,u$id$orig\_p,u$id$resp\_h,u$id$resp\_p);

#}

#event udp\_reply(u: connection)  
#{

# print fmt(“UDP PACKET | CONN: %s:%s \> %s:%s”,u$id$resp\_h,u$id$resp\_p,u$id$orig\_h,u$id$orig\_p);

#}

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [June 3, 2016, 4:50pm UTC](https://community.zeek.org/t/broccoli-code-not-working-not-receiving-any-events/4185/2 "2016-06-03T16:50:57Z")

</div>

Hello Sherine,

I am answering to basically most of your mails and a bit of your activity  
on IRC. Note that on IRC, you will nearly exclusively find people online  
weekdays during US daytime hours. During other times, you are unlikely to  
get an answer there - and it is a good idea to just keep your client  
running since you will probably get an answer, even if it might be hours  
later.

That being said - as I mentioned on IRC before, you should look at the  
broping examples of Broccoli on how to sent an event from Bro to broccoli.  
You will have to re-throw the event in Bro (so e.g. catch the tcp\_packet  
event and then send it off again under a different name, to which broccoli  
listens as given in the event argument for the connection).

However, I think generally you are trying to do the wrong thing here for a  
number of reasons.

First - broccoli is actually deprecated and will no longer be supported in  
future versions of Bro (it will be supported in 2.5, it might be in 2.6,  
it will probably not be in 2.7). Newer code might start looking into the  
new communication library called Broker.

Second - sending on events like tcp\_packet, udp\_packet, etc via the  
communication libraries seems like a bad idea. On even a quite low amount  
of network traffic, you will be generating enormous numbers of events that  
will have to be sent out via broccoli/broker. This will not scale to any  
significant link speed. In cluster mode, you get problems with event  
distribution on top of that (either you have to send events to the manager  
before or each cluster worker has to have its own broccoli/broker  
connection).

For your inter-arrival-time analysis, the best way probably would be to  
implement that directly in C++-code as a Bro module. However, implementing  
that will require quite a bit of understanding of the internal workings of  
Bro, which are not really documented too much; so you will have to do  
quite a bit of reading code and doing research yourself. So - that will  
probably take at least weeks of your time.

An example project that takes this approach is  
[https://github.com/bro/bro-plugins/tree/master/tcprs](https://github.com/bro/bro-plugins/tree/master/tcprs).

On a sidenote - it would be nice if you could put all your emails with  
questions on the same topic in one email thread - and also, if you put a  
bit more work into the way that you phrase your questions to make them  
easier to understand. Posting a stream of different mail messages is  
actually less likely to get a response (at least from me) - please  
remember that this is community support.

Johanna

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/broccoli-code-not-working-not-receiving-any-events/4185/3 "2022-05-06T15:43:44Z")

</div>


