# FTP::Info file\_size field

**URL:** <https://community.zeek.org/t/ftp-info-file-size-field/6272>\
**Category:** Zeek\
**Created:** [November 27, 2020, 10:39pm UTC](https://community.zeek.org/t/ftp-info-file-size-field/6272 "2020-11-27T22:39:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darren\_S](https://avatars.discourse-cdn.com/v4/letter/d/59ef9b/32.png) [@Darren\_S](https://community.zeek.org/u/Darren_S)\
**Post date:** [November 27, 2020, 10:39pm UTC](https://community.zeek.org/t/ftp-info-file-size-field/6272/1 "2020-11-27T22:39:53Z")

</div>

Greetings,

I have a series of FTP file upload tests we're analyzing with Zeek  
3.2.2. The environment is as follows:

- FTP server: vsftpd 3.0.3  
- FTP client: curl 7.64.0  
- EPSV mode  
- Uploads with STOR command

There are a number of fields documented for the FTP::Info record [1]  
that aren't logged (have "-" values for those fields) for these tests  
in ftp.log. One is `file_size`, documented as "Size of the file if the  
command indicates a file transfer." Logged records have values logged  
for args, mime\_type, and fuid. But there is no value logged for  
file\_size. The files have been extracted successfully, so the  
expectation is that given a STOR command was used ("...command  
indicates a file transfer") and that given a file was extracted and  
mime type identified, the file size would be logged in ftp.log. Is  
there potentially an issue in the analyzer?

$ egrep '#fields|FsRuCZYQDY8FtmyS2' ftp.log  
#fields ts uid id.orig\_h id.orig\_p id.resp\_h  
id.resp\_p user password command arg mime\_type  
file\_size reply\_code reply\_msg data\_channel.passive  
data\_channel.orig\_h data\_channel.resp\_h data\_channel.resp\_p  
fuid  
1606347082.807480 CNp3Rz21qqtfdKWnG9 10.1.1.5 59888  
x.x.219.95 9826 testuser \<redacted\> STOR  
ftp://x.x.219.95/home/testuser/archived-unencrypted.zip  
application/zip - 226 Transfer complete. - - - -  
&nbsp;&nbsp;FsRuCZYQDY8FtmyS2  
1606347082.972373 CNp3Rz21qqtfdKWnG9 10.1.1.5 59888  
x.x.219.95 9826 testuser \<redacted\> EPSV - - -  
229 Entering Extended Passive Mode (|||33369|) T 10.1.1.5  
x.x.219.95 33369 FsRuCZYQDY8FtmyS2

Also noticing that in files.log there is a record of the extracted  
file from the data channel, but no associated file name. Is this  
expected for FTP\_DATA since the data channel is just a stream of data  
with no indication of file name (i.e. not informed by the control  
channel)?

#fields ts fuid tx\_hosts rx\_hosts conn\_uids source  
depth analyzers mime\_type filename duration local\_orig  
&nbsp;&nbsp;&nbsp;is\_orig seen\_bytes total\_bytes missing\_bytes  
overflow\_bytes timedout parent\_fuid md5 sha1 sha256  
extracted extracted\_cutoff extracted\_size  
1606347082.859187 FsRuCZYQDY8FtmyS2 10.1.1.5 x.x.219.95  
C66As819fJARn0a3kj FTP\_DATA 0 EXTRACT,SHA1,MD5  
application/zip - 0.000170 - T 6187 - 0 0 F  
&nbsp;&nbsp;&nbsp;- 68a7676890bda812d1818269e9b942bc  
633cb66a0565b4ed049cf4d65ed689bfe973ee51 -  
FTP\_DATA-FsRuCZYQDY8FtmyS2.zip F -

[1] [https://docs.zeek.org/en/current/scripts/base/protocols/ftp/info.zeek.html#type-FTP::Info](https://docs.zeek.org/en/current/scripts/base/protocols/ftp/info.zeek.html#type-FTP::Info)

- Darren

---

<div class="post-metadata">

**Author:** ![Richard\_Bejtlich](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/richard_bejtlich/32/597_2.png) [@Richard\_Bejtlich](https://community.zeek.org/u/Richard_Bejtlich)\
**Post date:** [November 28, 2020, 12:15am UTC](https://community.zeek.org/t/ftp-info-file-size-field/6272/2 "2020-11-28T00:15:42Z")

</div>

Hello,

Can you share a pcap?

Sincerely,

Richard

---

<div class="post-metadata">

**Author:** ![seth](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/seth/32/642_2.png) [@seth](https://community.zeek.org/u/seth)\
**Post date:** [November 30, 2020, 4:13pm UTC](https://community.zeek.org/t/ftp-info-file-size-field/6272/3 "2020-11-30T16:13:57Z")

</div>

FTP is a tricky protocol due to the control/data split and as the documentation suggests, that field is filled out by information provided in the protocol. We apparently don't collect a file size anywhere for FTP STOR commands although from looking around on the internet, I'm seeing evidence that at least some FTP servers provide that information in the control channel after a file transfer is complete.

Agreed with Richard overall though. A pcap would absolutely be the best thing at this point so we can see exactly what's happening in Zeek in your specific case.

&nbsp;&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/ftp-info-file-size-field/6272/4 "2022-05-06T15:47:31Z")

</div>


