# configure problem

**URL:** <https://community.zeek.org/t/configure-problem/581>\
**Category:** Zeek\
**Created:** [September 17, 2004, 5:58pm UTC](https://community.zeek.org/t/configure-problem/581 "2004-09-17T17:58:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [September 17, 2004, 5:58pm UTC](https://community.zeek.org/t/configure-problem/581/1 "2004-09-17T17:58:21Z")

</div>

> In short, "./make install" fails because the file:  
> "scripts/bro.cfg.example" is missing.

Here's the file. It's also been fixed to be included in the next  
distribution.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

# Source file config for running bro

# On a linux system this file will normally exist in /etc/sysconfig  
# and will have the same filename as the RC start script which calls it.

# On a FreeBSD machine this file will normally reside in /usr/local/etc  
# and will have the same filename as the RC start script which calls it.

# The following variables are exported and needed by Bro at runtime  
# These are mostly undocumented. arrrrrr!!!!!!  
# BROLOGS  
# BROHOME  
# BROPATH

# host only format  
BRO\_HOSTNAME=`hostname | awk -F. ' { print } '`  
# FQDN format  
# HOSTNAME=`hostname`

# Directory containing Bro binaries  
BRO\_BIN\_DIR="${BROHOME}/bin"

# Filename of the Bro start policy  
# START\_POLICY="default.bro"  
BRO\_START\_POLICY="brolite.bro"

# Directory containing Bro logs  
BROLOGS="${BROHOME}/logs"  
export BROLOGS

# Log archive directory  
BRO\_LOG\_ARCHIVE="${BROHOME}/archive"

# Directory containing Bro signature files  
BRO\_SIG\_DIR="${BROHOME}/local/sigs"

# Bro policy paths  
BROPATH="\{BROHOME\}/policy:{BROHOME}/policy/local:\{BROHOME\}/policy/local\-priv:{BROHOME}/local/policy:${BROHOME}/site"  
export BROPATH

# Location of site specific policy and configurations  
BROSITE="${BROHOME}/site"

# Location of host specific policy and configurations  
BROHOST="${BROHOME}/host"

# A prefix to use when looking for local policy files to load.  
# BRO\_PREFIX="local"

# Location of the Bro executable  
BRO="${BRO\_BIN\_DIR}/bro"

# Base command line options.  
BRO\_ADD\_OPTS=" -W"  
# Turn on Bro's Watchdog feature  
BRO\_OPTS="${BRO\_ADD\_OPTS}"

# Interface name to listen on. The default is to use the busiest one found.  
BRO\_CAPTURE\_INTERFACE=""  
# Multiple interface should be specified as a space delimited list.  
# Examples:  
# CAPTURE\_INTERFACE="sk0 sk1 sk5"  
# CAPTURE\_INTERFACE="eth0 eth3"  
# CAPTURE\_INTERFACE="eth0"

# If set to YES and there are any signature files ending with .bro in $SIG\_DIR  
# then they will be started with bro. Set to NO to disable signatures  
# Set to YES to enable bro to run with 'signature matching' on (YES/NO)  
BRO\_USE\_SIGNATURES=YES

# Shoud a trace (tcpdump) file be created in the log directory (YES/NO)  
BRO\_CREATE\_TRACE\_FILE=NO

# How long to wait during checkpointing after startin a new Bro process and  
# stopping the old one. This value is in seconds  
BRO\_CHECKPOINT\_OVERLAP\_TIME=20

# Starting time for a report run (0001 is 12:01 am and 1201 is 12:01pm)  
BRO\_REPORT\_START\_TIME=0000

# How often (in hours) to generate an activity report  
BRO\_REPORT\_INTERVAL=24

# This is the how often to rotate the logs (in hours)  
BRO\_LOG\_ROTATE\_INTERVAL=24

# This is the how often to restart bro (in hours)  
BRO\_CHECKPOINT\_INTERVAL=24

# The maximum time allowed for a Bro process to cleanup and exit  
# This value is in seconds  
BRO\_MAX\_SHUTDOWN\_TIME=$(( 60 \* 60 \* 2 )) # 2 hours

# Use this to enable the init script to autorestart Bro in the event of an  
# unexpected shutdown. The value should be YES or NO  
BRO\_ENABLE\_AUTORESTART="YES"

# Maximum times to try to auto-restart Bro before giving up.  
# This is used by the bro-autorestart.sh script.  
BRO\_MAX\_RESTART\_ATTEMPTS=5

# Location of the run-time variable directory. This is normally /var/run/bro  
# and contains the pidfile and other temporal data.  
BRO\_RUNTIME\_DIR="/var/run/bro"

# Email address for local reports to be mailed to  
BRO\_EMAIL\_LOCAL="bro@localhost"

# Do you want to send external reports to a incident reporting org (e.g.: CERT, CIAC, etc)  
BRO\_EMAIL\_EXTERNAL="NO"

# Email address for remote reports to be mailed to  
BRO\_EMAIL\_REMOTE="BRO-IDS@bro-ids.org"

# User id to install and run Bro under  
BRO\_USER\_ID="bro"

# Site name for reports (i.e. LBNL, FOO.COM, BAZ.ORG)  
BRO\_SITE\_NAME=""

# Do you want to encrypt email reports (YES/NO)  
BRO\_ENCRYPT\_EMAIL="NO"

# Location of GPG binary or encrypting email  
BRO\_GPG\_BIN="/usr/local/bin/gpg"

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/configure-problem/581/2 "2022-05-06T15:37:09Z")

</div>


