# Enforce hex encoding in log output

**URL:** <https://community.zeek.org/t/enforce-hex-encoding-in-log-output/2557>\
**Category:** Zeek\
**Created:** [February 12, 2013, 4:38am UTC](https://community.zeek.org/t/enforce-hex-encoding-in-log-output/2557 "2013-02-12T04:38:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jessebowling](https://avatars.discourse-cdn.com/v4/letter/j/f9ae1b/32.png) [@jessebowling](https://community.zeek.org/u/jessebowling)\
**Post date:** [February 12, 2013, 4:38am UTC](https://community.zeek.org/t/enforce-hex-encoding-in-log-output/2557/1 "2013-02-12T04:38:44Z")

</div>

So I wanted some Bro to capture the contents of HTTP POST’s, and found in the archives that Seth had already written such a thing:

module HTTP;

export {

## The number of bytes that will be included in the http

## log from the client body.

const post\_body\_limit = 1024;

redef record Info += {  
post\_body: string &log &optional;  
};

}

event http\_entity\_data(c: connection, is\_orig: bool, length: count, data: string)  
{  
if ( is\_orig )  
{  
if ( ! c$http?$post\_body )  
c$http$post\_body = sub\_bytes(data, 0, post\_body\_limit);  
else if ( |c$http$post\_body| \< post\_body\_limit )  
c$http$post\_body = string\_cat(c$http$post\_body, sub\_bytes(data, 0, post\_body\_limit-|c$http$post\_body|));  
}  
}

So now my question is: in the output of the data, can we ensure that ALL data is hex encoded, even if it’s part of the ASCII character set? I need to put this data into a feed, and not being able to count on a delimiter is problematic…

Thanks,

Jesse

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [February 12, 2013, 5:06am UTC](https://community.zeek.org/t/enforce-hex-encoding-in-log-output/2557/2 "2013-02-12T05:06:31Z")

</div>

Just do this…

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( ! c$http?$post\_body )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;c$http$post\_body = bytestring\_to\_hexstr(sub\_bytes(data, 0, post\_body\_limit));  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;else if ( |c$http$post\_body| \< post\_body\_limit )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;c$http$post\_body = string\_cat(c$http$post\_body, bytestring\_to\_hexstr(sub\_bytes(data, 0, post\_body\_limit-|c$http$post\_body|)));

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/enforce-hex-encoding-in-log-output/2557/3 "2022-05-06T15:40:46Z")

</div>


