# check rx and tx hosts for files

**URL:** <https://community.zeek.org/t/check-rx-and-tx-hosts-for-files/4407>\
**Category:** Zeek\
**Created:** [October 10, 2016, 7:32pm UTC](https://community.zeek.org/t/check-rx-and-tx-hosts-for-files/4407 "2016-10-10T19:32:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fatema\_bannatwala](https://avatars.discourse-cdn.com/v4/letter/f/5f9b8f/32.png) [@fatema\_bannatwala](https://community.zeek.org/u/fatema_bannatwala)\
**Post date:** [October 10, 2016, 7:32pm UTC](https://community.zeek.org/t/check-rx-and-tx-hosts-for-files/4407/1 "2016-10-10T19:32:05Z")

</div>

Hi Brian,

I had the kind of same use-case where I had to exclude file extraction for certain subnets.  
Hence this is what I have done in my script:

# White list of subnets to exclude file extraction for.

global subnet\_map: table[subnet] of string = {  
[x.x.x.x/25] = “VIP subnet1”,  
[y.y.y.y/26] = “VIP subnet2”,  
[z.z.z.z/24] = “VIP subnet3”,  
} &default =“”;

event file\_sniff(f: fa\_file, meta: fa\_metadata)  
{

# check for right source to extract.

if(f$source != “HTTP”)  
return;

#check the right mime-type to extract.  
if ( ! meta?$mime\_type || meta$mime\_type !in ext\_map )  
return;

# get the recieving hosts from the record.

local rx\_addr: set[addr];  
rx\_addr = f$info$rx\_hosts;

# check if the rx host is in VIP subnets

for (i in rx\_addr)  
{  
if ( i in subnet\_map )  
{  
return;  
}  
}

if ( meta?$mime\_type )  
{  
local fname = fmt(“%s-%s.%s”, f$source, f$id, ext\_map[meta$mime\_type]);  
Files::add\_analyzer(f, Files::ANALYZER\_EXTRACT, [$extract\_filename=fname]);  
}  
}

You can define the rx or tx which you want to exclude/include and modify accordingly.  
I am sure there might be some more efficient ways to do this, I will let other more experience people to answer that 🙂

Hope this helps.

Thanks,  
Fatema.

---

<div class="post-metadata">

**Author:** ![Kellogg\_Brian\_GS\_IT](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@Kellogg\_Brian\_GS\_IT](https://community.zeek.org/u/Kellogg_Brian_GS_IT)\
**Post date:** [October 10, 2016, 7:34pm UTC](https://community.zeek.org/t/check-rx-and-tx-hosts-for-files/4407/2 "2016-10-10T19:34:37Z")

</div>

Thanks, I did something similar. Always concerned I’m doing it the hard way.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/check-rx-and-tx-hosts-for-files/4407/3 "2022-05-06T15:44:08Z")

</div>


