# Broker coding question

**URL:** <https://community.zeek.org/t/broker-coding-question/5320>\
**Category:** Zeek\
**Created:** [May 23, 2018, 8:54pm UTC](https://community.zeek.org/t/broker-coding-question/5320 "2018-05-23T20:54:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dopheide](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@dopheide](https://community.zeek.org/u/dopheide)\
**Post date:** [May 23, 2018, 8:54pm UTC](https://community.zeek.org/t/broker-coding-question/5320/1 "2018-05-23T20:54:53Z")

</div>

Maybe jumping the gun a little here, but I’ve started playing with the new Broker functions a bit and run into an issue that’s probably just lack of understanding on my part. I’ve crafted a policy specific for this discussion.

Basically, I’m trying to send data from the manager to my workers and it’s not showing up as I’d expect. In this policy you’ll see a couple different ways I thought were right based on the documentation and looking at other examples. One was using Broker::auto\_publish so any call to my ‘manager\_to\_workers’ event should go out automatically. The other is a straight Broker::publish.

When I run this and then check with “broctl print Dop::bourbon”, all I ever see is Eagle Rare, none of the published events appear to make it into the set.

Thanks,  
Dop

[broker-when.bro](https://community.zeek.org/uploads/short-url/cgcT2tMfTAAO2zM7t6b6r5cIMzI.bro) (878 Bytes)

---

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [May 24, 2018, 3:08am UTC](https://community.zeek.org/t/broker-coding-question/5320/2 "2018-05-24T03:08:05Z")

</div>

You're running into a longstanding inconsistency in the way Bro  
resolves event identifiers [1], which was also a source of confusion  
before Broker.

A general rule to follow when using event names in Bro is: if you  
define it inside a module/namespace, then just always use that  
namespace scoping when referring to the event name, so try replacing  
all references to "manager\_to\_workers" in your script with  
"Dop::manager\_to\_workers".

Another thing to note about that script is that a cluster will start  
worker nodes after the manager node, so I expect only the scheduled  
"Elijah Craig" event to consistently reach workers. Since all the  
other events happen at bro\_init() time (or very close to it), the  
worker has not yet connected.

You should also notice that dispatching via "event" will still call  
any local event handlers as it did before, but Broker::publish will  
not.

- Jon

[1] [https://bro-tracker.atlassian.net/browse/BIT-71](https://bro-tracker.atlassian.net/browse/BIT-71)

---

<div class="post-metadata">

**Author:** ![dopheide](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@dopheide](https://community.zeek.org/u/dopheide)\
**Post date:** [May 24, 2018, 2:47pm UTC](https://community.zeek.org/t/broker-coding-question/5320/3 "2018-05-24T14:47:58Z")

</div>

Ah, thanks. I knew I was missing something silly and I feel like others will run into this as well. What do you think about reflecting that in the Broker docs? I’m happy to make those changes and submit a pull request.

-Dop

---

<div class="post-metadata">

**Author:** ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)\
**Post date:** [May 24, 2018, 3:15pm UTC](https://community.zeek.org/t/broker-coding-question/5320/4 "2018-05-24T15:15:29Z")

</div>

Yeah, that will be good if you can suggest a place where it would have  
helped (others have indeed run into it already). Note that it's not  
just Broker / remote-communication that needs to obey this event  
naming restriction, it's event handling/dispatching in general.

- Jon

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/broker-coding-question/5320/5 "2022-05-06T15:45:49Z")

</div>


