# Coustom Signatures

**URL:** <https://community.zeek.org/t/coustom-signatures/988>\
**Category:** Zeek\
**Created:** [July 1, 2006, 6:39am UTC](https://community.zeek.org/t/coustom-signatures/988 "2006-07-01T06:39:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anandraj](https://avatars.discourse-cdn.com/v4/letter/a/6a8cbe/32.png) [@Anandraj](https://community.zeek.org/u/Anandraj)\
**Post date:** [July 1, 2006, 6:39am UTC](https://community.zeek.org/t/coustom-signatures/988/1 "2006-07-01T06:39:14Z")

</div>

Hi all,

For the following signature built-in the ../site/signatures.bro  
signature s2b-719-7-BRO { /\*a rename from s2b-719-7 to s2b-719-7-BRO \*/  
&nbsp;&nbsp;ip-proto == tcp  
&nbsp;&nbsp;src-port == 23  
&nbsp;&nbsp;event "TELNET root login"  
&nbsp;&nbsp;tcp-state established,responder  
&nbsp;&nbsp;payload /.\*login\x3A root/  
}

I could find a log in the Signatures-xxx.log

1151508123.667965:SensitiveSignature:10.50.27.117:23/tcp:10.50.25.122:2089/tcp:s2b-719-7-BRO:10.50.27.117:  
TELNET root login:t::

But when i added the following coustom signature in  
../site/signatures.bro  
i could not find a log in Signatures-xxx.log (The event occured i did a  
login as anand )

/\*Signature for the event when the user name is anand \*/  
signature telnet\_test{  
ip-proto == tcp  
src-port == 23  
event "TELNET anand login"  
tcp-state established,responder  
payload /.\*login: anand/  
}

i did try bro -s ../site/signatures.bro ! there was no response .. i had  
to do a ctrl + c !

Could someone help me on this !!

Thanks ,  
Anand

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [July 1, 2006, 5:46pm UTC](https://community.zeek.org/t/coustom-signatures/988/2 "2006-07-01T17:46:43Z")

</div>

Not sure I understand what you did. Where you running Bro on live  
traffic (then I suppose you also gave it the interface to listen  
on), or on a trace (then, similarly, the command line needs to  
include the trace file).

In general, the best way to debug such signature problems is to  
capture a small trace on which the signature should match and then  
first make sure that the packets' content indeed look like what the  
signature expects (e.g., using tcpdump). If it does, then making the  
signature less and less restrictive until it finally matches often  
helps to understand what the problem actually is.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/coustom-signatures/988/3 "2022-05-06T15:37:54Z")

</div>


