# file format

**URL:** <https://community.zeek.org/t/file-format/22>\
**Category:** Zeek\
**Created:** [October 12, 1998, 12:57am UTC](https://community.zeek.org/t/file-format/22 "1998-10-12T00:57:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_Deniman](https://avatars.discourse-cdn.com/v4/letter/d/e8c25b/32.png) [@Dave\_Deniman](https://community.zeek.org/u/Dave_Deniman)\
**Post date:** [October 12, 1998, 12:57am UTC](https://community.zeek.org/t/file-format/22/1 "1998-10-12T00:57:05Z")

</div>

We are a senior project group from the University of Colorado at Boulder.  
We are beginning research into intrusion detection and are considering  
using Bro. After browsing the source code, we have questions:

- is there an archive for this mailing list?  
- is there more documentation or any faqs specifically for Bro?  
- is a signature data file utilized? If so, what module(s) access it?  
- are there some example log files available?

We are currently waiting for the hardware to install Bro, but are trying  
to determine the formats of the signature file and log files for design  
purposes.

Any assistance would be greatly appreciated.

Thanks,  
Dave, Kelly, Jason, Mike, Paul

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/file-format/22/2 "2022-05-06T15:36:03Z")

</div>


