# files.log

**URL:** <https://community.zeek.org/t/files-log/4372>\
**Category:** Zeek\
**Created:** [September 28, 2016, 5:50pm UTC](https://community.zeek.org/t/files-log/4372 "2016-09-28T17:50:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![erik\_clark](https://avatars.discourse-cdn.com/v4/letter/e/ba8739/32.png) [@erik\_clark](https://community.zeek.org/u/erik_clark)\
**Post date:** [September 28, 2016, 5:50pm UTC](https://community.zeek.org/t/files-log/4372/1 "2016-09-28T17:50:19Z")

</div>

98% of all entries in our files.log are null values. Is this to be expected?

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 29, 2016, 2:16am UTC](https://community.zeek.org/t/files-log/4372/2 "2016-09-29T02:16:50Z")

</div>

What analyzers are the files coming from?

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![erik\_clark](https://avatars.discourse-cdn.com/v4/letter/e/ba8739/32.png) [@erik\_clark](https://community.zeek.org/u/erik_clark)\
**Post date:** [September 29, 2016, 11:22am UTC](https://community.zeek.org/t/files-log/4372/3 "2016-09-29T11:22:49Z")

</div>

According to splunk/files.log, these list “pe\_xor, md5, sha1,sha256” in the analyzer section. Its actually a lot more than that, and slight variations. Generally speaking, almost every entry is a variant of that 4 analyzers. Could this be an issue with the pe\_xor module? Moreover, files that we have filenames for (f.txt from google for instance) have the same analyzers running as well.

---

<div class="post-metadata">

**Author:** ![erik\_clark](https://avatars.discourse-cdn.com/v4/letter/e/ba8739/32.png) [@erik\_clark](https://community.zeek.org/u/erik_clark)\
**Post date:** [September 29, 2016, 11:33am UTC](https://community.zeek.org/t/files-log/4372/4 "2016-09-29T11:33:26Z")

</div>

As an aside, even after disabling pe\_xor (out of curiosity), we are still not seeing the filenames. Out of 74,000 file.log entries, only 620 have filenames. Of those, 99.52% of them are f.txt filenames (from google)…

---

<div class="post-metadata">

**Author:** ![erik\_clark](https://avatars.discourse-cdn.com/v4/letter/e/ba8739/32.png) [@erik\_clark](https://community.zeek.org/u/erik_clark)\
**Post date:** [September 29, 2016, 11:42am UTC](https://community.zeek.org/t/files-log/4372/5 "2016-09-29T11:42:47Z")

</div>

Sorry, last post. Found [http://mailman.icsi.berkeley.edu/pipermail/bro/2014-April/006893.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2014-April/006893.html). This is inline with what I was discovering from my files.log. I will see if I can expand the framework to do correlation to get this info.

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 29, 2016, 12:37pm UTC](https://community.zeek.org/t/files-log/4372/6 "2016-09-29T12:37:04Z")

</div>

Ohh... I see now. You didn't specify that it was the filename field that was null. Unfortunately I think that the current behavior is best as the default behavior. I suspect that at some point we'll see a package show up in the Bro package manager which adds some heuristically driven filenames (i.e. pulling "filenames" from URLs).

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/files-log/4372/7 "2022-05-06T15:44:04Z")

</div>


