# Capturing filename

**URL:** <https://community.zeek.org/t/capturing-filename/6427>\
**Category:** Zeek\
**Created:** [December 7, 2021, 11:15am UTC](https://community.zeek.org/t/capturing-filename/6427 "2021-12-07T11:15:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![clopmz](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@clopmz](https://community.zeek.org/u/clopmz)\
**Post date:** [December 7, 2021, 11:15am UTC](https://community.zeek.org/t/capturing-filename/6427/1 "2021-12-07T11:15:16Z")

</div>

Hi all,

Is it possible to extract only the filename without extracting and storing it? Only the filename ….

Regards,

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [December 7, 2021, 7:25pm UTC](https://community.zeek.org/t/capturing-filename/6427/2 "2021-12-07T19:25:18Z")

</div>

Is the filename field in the files.log what you are looking for?

---

<div class="post-metadata">

**Author:** ![clopmz](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@clopmz](https://community.zeek.org/u/clopmz)\
**Post date:** [December 10, 2021, 7:11am UTC](https://community.zeek.org/t/capturing-filename/6427/3 "2021-12-10T07:11:05Z")

</div>

Hi Justin,

No, it is not.

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [December 10, 2021, 12:11pm UTC](https://community.zeek.org/t/capturing-filename/6427/4 "2021-12-10T12:11:23Z")

</div>

Can you share a pcap of your traffic, or at least upload it to [try.zeek.org](http://try.zeek.org) and share the URL? Some details might help us answer your question…

Sincerely,

Richard

---

<div class="post-metadata">

**Author:** ![clopmz](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@clopmz](https://community.zeek.org/u/clopmz)\
**Post date:** [December 12, 2021, 11:14am UTC](https://community.zeek.org/t/capturing-filename/6427/5 "2021-12-12T11:14:03Z")

</div>

Good morning,

Sorry for this later answer …. Here it is a pcap … Exists a filename README.mirrors.txt as you can see in my http.log (attached screenshot) …. I have attached files.log also where you can see that “filename” field is not created.

Many thanks for your help.

 ![](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/1b4dd0cd000aaf7ef37c8c04d0efb63e546365f2.png)

 ![](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/eb209fdcbf7bc09cfa47bca341c8b9a442b0af3a.png)

[filename\_capture.tar](https://community.zeek.org/uploads/short-url/g9Udvy4wR7Zh9B1HCBdbyD8UI59.tar) (5.5 KB)

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [December 13, 2021, 3:04pm UTC](https://community.zeek.org/t/capturing-filename/6427/6 "2021-12-13T15:04:15Z")

</div>

Thanks for sharing the pcap.

It doesn’t actually reflect transferring that file. Here is the [try.zeek.org](http://try.zeek.org) output:

[https://try.zeek.org/#/tryzeek/saved/550762](https://try.zeek.org/#/tryzeek/saved/550762)

Here is a transcript from Wireshark:

GET /debian/README.mirrors.txt HTTP/1.1  
User-Agent: Wget/1.19.5 (linux-gnu)  
Accept: _/_  
Accept-Encoding: identity  
Host: [ftp.au.debian.org](http://ftp.au.debian.org)  
Connection: Keep-Alive

HTTP/1.1 200 OK  
Server: Apache/2.4.10 (Debian)  
Last-Modified: Sat, 04 Mar 2017 20:08:51 GMT  
ETag: “56-549ed3b25abfb”  
Accept-Ranges: bytes  
Content-Length: 86  
Vary: Accept-Encoding  
Keep-Alive: timeout=5, max=100  
Connection: Keep-Alive  
Content-Type: text/plain

The list of Debian mirror sites is available here: [https://www.debian.org/mirror/list](https://www.debian.org/mirror/list)

In other words, the “file” here is text/plain and is only the sentence “The list of Debian mirror sites is available here: [https://www.debian.org/mirror/list](https://www.debian.org/mirror/list)”.

Sincerely,

Richard

 ![files.log.png](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/1b4dd0cd000aaf7ef37c8c04d0efb63e546365f2.png)

 ![http.log.png](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/eb209fdcbf7bc09cfa47bca341c8b9a442b0af3a.png)

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [December 13, 2021, 3:23pm UTC](https://community.zeek.org/t/capturing-filename/6427/7 "2021-12-13T15:23:03Z")

</div>

I have a package somewhere that sets the filename field based on the  
http url. Zeek only does this by default if there is a  
content-disposition or content-type header that indicates a specific  
filename, but many file downloads don't have that header. It can  
produce a lot of noise, but it might be what you are asking for.

I'll see about making sure it is updated for 4.1 and work on getting  
it added to the package manager.

---

<div class="post-metadata">

**Author:** ![clopmz](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@clopmz](https://community.zeek.org/u/clopmz)\
**Post date:** [December 13, 2021, 3:35pm UTC](https://community.zeek.org/t/capturing-filename/6427/8 "2021-12-13T15:35:08Z")

</div>

Exactly Justin … this is what I am looking for …. Actually I am using Zeek 4.0.4 … can I enable it reconfiguring?

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [December 15, 2021, 10:26pm UTC](https://community.zeek.org/t/capturing-filename/6427/9 "2021-12-15T22:26:57Z")

</div>

Hi!

Give this package a try: [https://github.com/corelight/http-more-files-names](https://github.com/corelight/http-more-files-names)

I didn't add it to the package manager metadata yet, but you can test it via

zkg install [https://github.com/corelight/http-more-files-names](https://github.com/corelight/http-more-files-names)

if you can confirm that works ok, I'll get it added to the package index.

---

<div class="post-metadata">

**Author:** ![clopmz](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@clopmz](https://community.zeek.org/u/clopmz)\
**Post date:** [December 16, 2021, 12:19pm UTC](https://community.zeek.org/t/capturing-filename/6427/10 "2021-12-16T12:19:35Z")

</div>

Hi Justin,

Tested and it works!! …. Many thanks.

 ![](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/a59e4708b49e49da6ccc6ae31b079ead0262f6b8.png)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/capturing-filename/6427/11 "2022-05-06T15:47:48Z")

</div>


