# Event namespaces

**URL:** <https://community.zeek.org/t/event-namespaces/5880>\
**Category:** Zeek\
**Created:** [October 23, 2019, 6:31pm UTC](https://community.zeek.org/t/event-namespaces/5880 "2019-10-23T18:31:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeff\_Barber1](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@Jeff\_Barber1](https://community.zeek.org/u/Jeff_Barber1)\
**Post date:** [October 23, 2019, 6:31pm UTC](https://community.zeek.org/t/event-namespaces/5880/1 "2019-10-23T18:31:17Z")

</div>

At [https://docs.zeek.org/en/stable/frameworks/broker.html#a-reminder-about-events-and-module-namespaces](https://docs.zeek.org/en/stable/frameworks/broker.html#a-reminder-about-events-and-module-namespaces), following a code sample, there is the statement:

> _This code runs without errors, however, the local my\_event handler will never be called and also not any remote handlers either, even if Broker::auto\_publish was used elsewhere for it._

My tests have not supported that assertion: the event handler is invoked - even via auto\_publish. If it is so, how/when exactly would it manifest? Are there other factors that might cause it to be true in some cases? (Say, the same event name in a different namespace?)

Just trying to figure out how careful I need to be of namespace issues. My tests have generally shown that if you get the namespace of some script element wrong, the script parsing stage gives you an ‘undefined’ right out of the gate.

Thanks,  
Jeff

---

<div class="post-metadata">

**Author:** ![dopheide](https://avatars.discourse-cdn.com/v4/letter/d/74df32/32.png) [@dopheide](https://community.zeek.org/u/dopheide)\
**Post date:** [October 23, 2019, 7:12pm UTC](https://community.zeek.org/t/event-namespaces/5880/2 "2019-10-23T19:12:27Z")

</div>

Hhmm… I get the expected non-working behavior:

====== TEST 1 ======

# cat test.zeek

module MyModule;

export {  
global my\_event: event();  
}

event my\_event()  
{  
print “got my event”;  
}

event zeek\_init()  
{  
event my\_event();  
schedule 10sec { my\_event() };  
}

# zeek -i eth0 test.zeek

listening on eth0

(nothing else)

======= TEST 2 =======

# cat test2.zeek

module MyModule;

export {  
global my\_event: event();  
}

event my\_event()  
{  
print “got my event”;  
}

event zeek\_init()  
{  
event MyModule::my\_event();  
schedule 10sec { MyModule::my\_event() };  
}

# zeek -i eth0 test2.zeek

listening on eth0

got my event  
got my event

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [October 23, 2019, 7:15pm UTC](https://community.zeek.org/t/event-namespaces/5880/3 "2019-10-23T19:15:17Z")

</div>

Take a look at these: [https://github.com/zeek/zeek/issues/163](https://github.com/zeek/zeek/issues/163) & [https://bro-tracker.atlassian.net/browse/BIT-984](https://bro-tracker.atlassian.net/browse/BIT-984)

I’ve run into this issue, and my best practice is to use fully scoped event names, which is the recommended workaround.

Jim

---

<div class="post-metadata">

**Author:** ![Jeff\_Barber1](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@Jeff\_Barber1](https://community.zeek.org/u/Jeff_Barber1)\
**Post date:** [October 23, 2019, 11:16pm UTC](https://community.zeek.org/t/event-namespaces/5880/4 "2019-10-23T23:16:37Z")

</div>

Ah. Thanks, Jim.

That’s what I wanted to understand: From your second link, it’s clear that the “global” declaration on the event is what causes the issue. If you simply define an event (without global) and use it within the same script file, there seems to be no problem.

Cheers,  
Jeff

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/event-namespaces/5880/5 "2022-05-06T15:46:50Z")

</div>


