# Disabling an analyzer in weird

**URL:** <https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712>\
**Category:** Zeek\
**Created:** [March 8, 2017, 5:15pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712 "2017-03-08T17:15:04Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 8, 2017, 5:15pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/1 "2017-03-08T17:15:04Z")

</div>

Topic 🙂 I'd like to have bro not dump non-rfc compliant syslog messages in the weird file. How can I go about doing that? Thank you.

James

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [March 8, 2017, 6:17pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/2 "2017-03-08T18:17:57Z")

</div>

> Topic 🙂 I'd like to have bro not dump non-rfc compliant syslog  
> messages in the weird file. How can I go about doing that? Thank you.

Add a filter for the log might be an option:  
[https://www.bro.org/sphinx-git/frameworks/logging.html#filter-log-records](https://www.bro.org/sphinx-git/frameworks/logging.html#filter-log-records)

Jan

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 10, 2017, 7:18pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/3 "2017-03-10T19:18:45Z")

</div>

Thanks Jan. So I did more digging...this used to work in 2.4.1:

[http://mailman.icsi.berkeley.edu/pipermail/bro/2014-July/007178.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2014-July/007178.html)

But now no longer...I guess I don't want to see binpac exceptions in weird. Any folks have any thoughts on this? Thank you.

James

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [March 10, 2017, 7:30pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/4 "2017-03-10T19:30:05Z")

</div>

> Thanks Jan. So I did more digging...this used to work in 2.4.1:
> 
> [http://mailman.icsi.berkeley.edu/pipermail/bro/2014-July/007178.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2014-July/007178.html)
> 
> But now no longer...I guess I don't want to see binpac exceptions in  
> weird. Any folks have any thoughts on this? Thank you.

So if disabling the syslog analyzer completely is ok for you that should  
just work fine with 2.5. Do you see any errors?

Jan

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 10, 2017, 9:22pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/5 "2017-03-10T21:22:49Z")

</div>

Thanks Jan,

I got this to fly with disabling the analyzer, but as I look at the weird.log there are several items I’d like to filter out. For example:

dns\_unmatched\_msg  
inappropriate\_FIN

and others. I’ve looked at the code snippet as shown below:

function http\_only(rec: Conn::Info) : bool  
{

# Record only connections with successfully analyzed HTTP traffic

return rec?$service && rec$service == “http”;  
}

event bro\_init()  
{  
local filter: Log::Filter = [$name=“http-only”, $path=“conn-http”,  
$pred=http\_only];  
Log::add\_filter(Conn::LOG, filter);  
}

and, as usual when I stare at bro code snippets, I’m completely lost. I get that the above creates a new log and only http from conn.log, but I have no idea how to tweak this to filter out things from weird.log. I’ve looked at:

[http://try.bro.org/#/?example=logs-filter-logs](http://try.bro.org/#/?example=logs-filter-logs)  
[http://blog.bro.org/2012/02/filtering-logs-with-bro.html](http://blog.bro.org/2012/02/filtering-logs-with-bro.html)  
[https://www.bro.org/development/projects/logging-api.html](https://www.bro.org/development/projects/logging-api.html)

I see a lot of these are about splitting into new logs or filtering out fields…none of which I want to do. Any additional guidance on negating entries from logs would be excellent. Thank you…bro always makes me feel stupid 8-/

James

---

<div class="post-metadata">

**Author:** ![Shane\_Filus](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@Shane\_Filus](https://community.zeek.org/u/Shane_Filus)\
**Post date:** [March 10, 2017, 9:45pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/6 "2017-03-10T21:45:11Z")

</div>

Hi James,

Specifically to weird logging, you can redef individual messages:

&nbsp;&nbsp;&nbsp;&nbsp;redef Weird::actions["dns\_unmatched\_msg"] = Weird::ACTION\_IGNORE;  
&nbsp;&nbsp;&nbsp;&nbsp;redef Weird::actions["dns\_unmatched\_reply"] = Weird::ACTION\_IGNORE;

[https://www.bro.org/sphinx/scripts/base/frameworks/notice/weird.bro.html](https://www.bro.org/sphinx/scripts/base/frameworks/notice/weird.bro.html)

Re-reading, didn't realize there were more actions than IGNORE(and LOG).  
Smart.

Thanks!

Shane

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [March 10, 2017, 10:05pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/7 "2017-03-10T22:05:20Z")

</div>

> Specifically to weird logging, you can redef individual messages:
> 
> &nbsp;&nbsp;&nbsp;&nbsp;redef Weird::actions["dns\_unmatched\_msg"] = Weird::ACTION\_IGNORE;  
> &nbsp;&nbsp;&nbsp;&nbsp;redef Weird::actions["dns\_unmatched\_reply"] = Weird::ACTION\_IGNORE;

Just remembered that as I read "dns\_unmatched\_reply". Thanks for helping  
out, Shane!

> Re-reading, didn't realize there were more actions than IGNORE(and LOG).  
> Smart.

That's the reason why this mechanism would be preferred for filtering weird.

Thanks,  
Jan

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 10, 2017, 11:11pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/8 "2017-03-10T23:11:21Z")

</div>

Perfect...thanks Shane and Jan...I'll give it a go and report my findings.

James

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 10, 2017, 11:28pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/9 "2017-03-10T23:28:02Z")

</div>

Well I'm certainly close. Thanks to the redef I'm able to squelch out a lot of noise, but alas, not the binpac exception. If I disable the analyzer I don't get any syslog.log file, so that's not what I need in this case. I'll keep digging..thanks again for all the help.

James

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [March 11, 2017, 8:46pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/10 "2017-03-11T20:46:53Z")

</div>

Hi James,

> Well I'm certainly close. Thanks to the redef I'm able to squelch out a  
> lot of noise, but alas, not the binpac exception. If I disable the  
> analyzer I don't get any syslog.log file, so that's not what I need in  
> this case. I'll keep digging..thanks again for all the help.

if that particular notice is not listed in Weird::actions you can still  
just filter manually. Something like that might work for you:  
[http://try.bro.org/#/trybro/saved/130377](http://try.bro.org/#/trybro/saved/130377)

Jan

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 11, 2017, 11:36pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/11 "2017-03-11T23:36:20Z")

</div>

Thanks a bunch Jan…I’ll give that a test and report my findings 😌

James

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 13, 2017, 5:26pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/12 "2017-03-13T17:26:42Z")

</div>

Well I gave it a shot...no go though:

1489425830.509505 CD8sYx3dttq6ynlg2c x.x.x.x 51132 x.x.x.x 514 binpac exception: string mismatch at /home/build/bro-2.5/src/analyzer/protocol/syslog/syslog-protocol.pac:8: \x0aexpected pattern: "[[:digit:]]+"\x0aactual data: "\<snip\>x09MSWinEventLog\x091\x09Application\x09674838\x09Mon Mar 13 11:23:50 \<snip\> \x0a" - F worker-3-5

Ok Seth...how does stop either a) weird from analyzing a protocol, or b) logging binpac errors? Thanks.

James

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [March 13, 2017, 7:33pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/13 "2017-03-13T19:33:55Z")

</div>

Hi James,

> Well I gave it a shot...no go though:
> 
> 1489425830.509505 CD8sYx3dttq6ynlg2c x.x.x.x 51132  
> x.x.x.x 514 binpac exception: string mismatch at  
> /home/build/bro-2.5/src/analyzer/protocol/syslog/syslog-protocol.pac:8:  
> \x0aexpected pattern: "[[:digit:]]+"\x0aactual data:  
> "\<snip\>x09MSWinEventLog\x091\x09Application\x09674838\x09Mon Mar 13  
> 11:23:50 \<snip\> \x0a" - F worker-3-5

How did you customize the filter\_weird function to match that line?  
Looks like the name field also contains some context-dependent info, so  
that you might need a regex. However, if you see a lot of this, it might  
be a good idea to dig deeper into the analyzer. Can you provide a pcap  
for testing?

Jan

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 13, 2017, 8:02pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/14 "2017-03-13T20:02:05Z")

</div>

Hi Jan,

Thanks for looking at this...I don't want to be a pest and we can take this off list if we need to so as not to drive all the smart people crazy 🙂 Here's what I added:

function filter\_weird (rec: Weird::Info) : bool  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return rec$name ! in set("binpac exception");  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

event bro\_init()  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local filter: Log::Filter = Log::get\_filter(Weird::LOG, "default");  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;filter$pred=filter\_weird;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Log::add\_filter(Weird::LOG, filter);  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

This is getting "syslogs" from Windows machines via a third party app. Clearly not adhering to the RFC. As for pcap, I cannot as this is sensitive data ☹ I can share more details off list if needed. Thank you.

James

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [March 13, 2017, 8:49pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/15 "2017-03-13T20:49:11Z")

</div>

Big thanks to Jan...I have so much to learn about bro 8-| Anyway solution below for filtering out binpac exception:

function filter\_weird (rec: Weird::Info) : bool  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return /binpac exception/ ! in rec$name;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

event bro\_init()  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local filter: Log::Filter = Log::get\_filter(Weird::LOG, "default");  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;filter$pred=filter\_weird;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Log::add\_filter(Weird::LOG, filter);  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

Thanks again Jan!

James

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/disabling-an-analyzer-in-weird/4712/16 "2022-05-06T15:44:42Z")

</div>


