# File log

**URL:** <https://community.zeek.org/t/file-log/3294>\
**Category:** Zeek\
**Created:** [October 1, 2014, 1:32pm UTC](https://community.zeek.org/t/file-log/3294 "2014-10-01T13:32:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Halliday](https://avatars.discourse-cdn.com/v4/letter/p/838e76/32.png) [@Paul\_Halliday](https://community.zeek.org/u/Paul_Halliday)\
**Post date:** [October 1, 2014, 1:32pm UTC](https://community.zeek.org/t/file-log/3294/1 "2014-10-01T13:32:43Z")

</div>

Is it normal for the ‘filename’ field to always be empty? The mime\_type is almost always identified but the filename field is always ‘-’

application/vnd.ms-cab-compressed -  
application/x-dosexec -  
text/plain -  
application/x-dosexec -  
text/plain -  
application/vnd.ms-fontobject -  
application/vnd.ms-fontobject -  
application/vnd.ms-fontobject -  
application/octet-stream -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/x-dosexec -  
application/vnd.ms-cab-compressed -  
image/jpeg -  
image/jpeg -  
image/jpeg -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/x-dosexec -  
application/vnd.ms-cab-compressed -  
text/plain -  
text/html -  
text/html -  
application/x-dosexec -  
application/vnd.ms-cab-compressed -  
application/x-dosexec -  
application/vnd.ms-cab-compressed -  
application/x-dosexec -  
image/jpeg -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/x-dosexec -  
text/plain -  
image/jpeg -  
application/vnd.ms-cab-compressed -  
application/octet-stream -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
image/jpeg -  
image/jpeg -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
image/jpeg -  
application/x-dosexec -  
application/x-dosexec -  
application/vnd.ms-cab-compressed -  
application/vnd.ms-cab-compressed -  
text/html -  
text/html -

Thanks.

---

<div class="post-metadata">

**Author:** ![Hosom\_Stephen\_M](https://avatars.discourse-cdn.com/v4/letter/h/d26b3c/32.png) [@Hosom\_Stephen\_M](https://community.zeek.org/u/Hosom_Stephen_M)\
**Post date:** [October 1, 2014, 1:44pm UTC](https://community.zeek.org/t/file-log/3294/2 "2014-10-01T13:44:31Z")

</div>

This is normal. Filename is used for protocols that identify the file name when it is in transit on the network (like HTTP). Generally though… you don’t actually want the filename, so this doesn’t have much impact on Bro’s ability to do cool stuff with files (how would you deal with a trillion copies of index.html, for example?).

---

<div class="post-metadata">

**Author:** ![Paul\_Halliday](https://avatars.discourse-cdn.com/v4/letter/p/838e76/32.png) [@Paul\_Halliday](https://community.zeek.org/u/Paul_Halliday)\
**Post date:** [October 1, 2014, 2:27pm UTC](https://community.zeek.org/t/file-log/3294/3 "2014-10-01T14:27:26Z")

</div>

Good to know. Out of curiosity though, if the field is of little value then why even have it? (I have to deal with a trillion copies of ‘-’)

😉

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [October 1, 2014, 3:07pm UTC](https://community.zeek.org/t/file-log/3294/4 "2014-10-01T15:07:05Z")

</div>

For a little more explanation, I'll point to a mailing list post I did a while ago:  
&nbsp;&nbsp;[http://marc.info/?l=bro&m=139882790812212&w=2](http://marc.info/?l=bro&m=139882790812212&w=2)

I'm not sure that I'd say that the field is of little value though. It's actually pretty valuable, the only problem is that for the most frequently seen protocol in your files log (HTTP), filename are rarely made available. If you look at SMTP traffic, you will much more frequently see that attachments have filenames.

Also, for the upcoming SMB analyzer, filenames are always (or should always) be available.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/file-log/3294/5 "2022-05-06T15:42:07Z")

</div>


