# Capturing and analyzing IGMP packets

**URL:** <https://community.zeek.org/t/capturing-and-analyzing-igmp-packets/937>\
**Category:** Zeek\
**Created:** [March 18, 2006, 7:31am UTC](https://community.zeek.org/t/capturing-and-analyzing-igmp-packets/937 "2006-03-18T07:31:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [March 18, 2006, 7:31am UTC](https://community.zeek.org/t/capturing-and-analyzing-igmp-packets/937/1 "2006-03-18T07:31:37Z")

</div>

> I am wondering if Bro is able to capture and analyze IGMP packets ?

Bro doesn't have an IGMP analyzer. (Contributions for this welcome!)

> I tried to turn all filters off ("redef capture\_filters = {};" at the end of  
> brolite-sigs.bro)
> 
> I built a very simple signature:
> 
> signature header3  
> {  
> &nbsp;&nbsp;src-ip == 10.92.39.3  
> &nbsp;&nbsp;event "Header 3"  
> }
> 
> When I run with this on a trace containing only IGMP traffic, nothing appends  
> even though there is plenty of packets with src-ip == 10.92.39.3 in the trace.

You'll need to redef capture\_filters so that it in some fashion includes  
this traffic.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/capturing-and-analyzing-igmp-packets/937/2 "2022-05-06T15:37:48Z")

</div>


