# File name from fa\_file

**URL:** <https://community.zeek.org/t/file-name-from-fa-file/3853>\
**Category:** Zeek\
**Created:** [September 29, 2015, 5:08pm UTC](https://community.zeek.org/t/file-name-from-fa-file/3853 "2015-09-29T17:08:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pigott\_Nathan](https://avatars.discourse-cdn.com/v4/letter/p/df705f/32.png) [@Pigott\_Nathan](https://community.zeek.org/u/Pigott_Nathan)\
**Post date:** [September 29, 2015, 5:08pm UTC](https://community.zeek.org/t/file-name-from-fa-file/3853/1 "2015-09-29T17:08:01Z")

</div>

Hello,

I’m having problems getting file names from fa\_file - the field f$info$filename is showing up uninitialized on every single fa\_file in all my tests. Is there a known reason why this would be happening? I’m using Bro 2.3, but I tested on 2.4 as well and got the same results.

Are there any alternative ways to get file names? For now I’m parsing the URL returned by Files::describe(f), but this does not work if the URL doesn’t contain the file name, or if the file was transferred with a protocol other than HTTP.

Thanks,  
Nathan Pigott

---

<div class="post-metadata">

**Author:** ![Hosom\_Stephen\_M](https://avatars.discourse-cdn.com/v4/letter/h/d26b3c/32.png) [@Hosom\_Stephen\_M](https://community.zeek.org/u/Hosom_Stephen_M)\
**Post date:** [September 29, 2015, 5:26pm UTC](https://community.zeek.org/t/file-name-from-fa-file/3853/2 "2015-09-29T17:26:57Z")

</div>

Filename does not always exist. That field is only created under circumstances where the protocol has a portion that would tell the server or client receiving the file what the name should be—most commonly that applies to HTTP. What is it that you’re trying to do with filenames, or what information are you attempting to derive from them? Generally it isn’t wise to trust filenames that you see on the wire for a whole lot.

---

<div class="post-metadata">

**Author:** ![Pigott\_Nathan](https://avatars.discourse-cdn.com/v4/letter/p/df705f/32.png) [@Pigott\_Nathan](https://community.zeek.org/u/Pigott_Nathan)\
**Post date:** [September 29, 2015, 5:56pm UTC](https://community.zeek.org/t/file-name-from-fa-file/3853/3 "2015-09-29T17:56:38Z")

</div>

Filename does not always exist. That field is only created under circumstances where the protocol has a portion that would tell the server or client receiving the file what the name should be—most commonly that applies to HTTP. What is it that you’re trying to do with filenames, or what information are you attempting to derive from them? Generally it isn’t wise to trust filenames that you see on the wire for a whole lot.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/file-name-from-fa-file/3853/4 "2022-05-06T15:43:07Z")

</div>


