# Empty reports!!

**URL:** <https://community.zeek.org/t/empty-reports/789>\
**Category:** Zeek\
**Created:** [June 21, 2005, 6:29pm UTC](https://community.zeek.org/t/empty-reports/789 "2005-06-21T18:29:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Angelita\_de\_Cassia\_C](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@Angelita\_de\_Cassia\_C](https://community.zeek.org/u/Angelita_de_Cassia_C)\
**Post date:** [June 21, 2005, 6:29pm UTC](https://community.zeek.org/t/empty-reports/789/1 "2005-06-21T18:29:43Z")

</div>

Administrators,

I have bro version bro-0.9a9 running. I see files in /usr/local/bro/logs correctly, but the reports are empty.

The other problem is the /usr/local/bro/archive direttory is empty too.

What can I do to generate the correctly reports?

I tested with one and two interfaces (etho and eth1), I’m using Red Hat Enterprise ES 3.

I saw the traffice using tcpdump.

Thanks!  
Angelita

---

<div class="post-metadata">

**Author:** ![Brian\_Tierney](https://avatars.discourse-cdn.com/v4/letter/b/13edae/32.png) [@Brian\_Tierney](https://community.zeek.org/u/Brian_Tierney)\
**Post date:** [June 27, 2005, 9:21pm UTC](https://community.zeek.org/t/empty-reports/789/2 "2005-06-27T21:21:04Z")

</div>

The report generation component of Bro is very much still in the "pre-alpha" stages, and the student  
who was working on this is now working on another project.

I'll try to answer a couple of your questions:

1) scan reporting is off by default, the reports were too long with all the scans included  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;(Im not sure how to turn them on)  
2) by default, the report scripts look for "yesterdays" data, so you have to collect 1 days data,  
then run the report  
3) there should be nothing in the /usr/local/bro/archive directory unless you are running  
the cron script: bro\_log\_compress.sh

You'll likely need to modify the report generation scripts by hand to get them to generate  
exactly what you want.

Hope this helps.

---

<div class="post-metadata">

**Author:** ![Angelita\_de\_Cassia\_C](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@Angelita\_de\_Cassia\_C](https://community.zeek.org/u/Angelita_de_Cassia_C)\
**Post date:** [July 19, 2005, 9:20pm UTC](https://community.zeek.org/t/empty-reports/789/3 "2005-07-19T21:20:24Z")

</div>

Brian,

Do you have some news about the report project ? I didn't obtain results  
with reports, it generates empty. ☹

And I need to analyse the alerts in detail. I need to identify if alerts are  
scan ou what kind of attacks, or if they are false positives. Do you  
understand me?

The logs are not enough to obtain these information.

Thanks  
Angelita

---

<div class="post-metadata">

**Author:** ![Brian\_Tierney](https://avatars.discourse-cdn.com/v4/letter/b/13edae/32.png) [@Brian\_Tierney](https://community.zeek.org/u/Brian_Tierney)\
**Post date:** [July 20, 2005, 9:27pm UTC](https://community.zeek.org/t/empty-reports/789/4 "2005-07-20T21:27:36Z")

</div>

The reports are just a reformated version of the information in the Alarm file.  
There is very little new info, it is just easier to read the report.

Do you have lots of entries in your alarm file?

To separate "attacks" from "false positives" usually requires detailed knowledge  
of your traffic, and what traffic is legitimate and what is not.

The reports will not help with this.

Hope this helps.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/empty-reports/789/5 "2022-05-06T15:37:32Z")

</div>


