# How to control when bro logs events

**URL:** <https://community.zeek.org/t/how-to-control-when-bro-logs-events/27>\
**Category:** Zeek\
**Created:** [October 15, 1998, 3:20am UTC](https://community.zeek.org/t/how-to-control-when-bro-logs-events/27 "1998-10-15T03:20:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [October 15, 1998, 3:20am UTC](https://community.zeek.org/t/how-to-control-when-bro-logs-events/27/1 "1998-10-15T03:20:29Z")

</div>

> How quickly  
> is an event (say, a TCP session finishing the normal way) logged? How can  
> I control this?

Logging occurs whenever your policy script executes a "log" statement,  
and it goes out immediately via syslog(). If you're printing using  
"print" to a file, then it's block buffered. Adding a flush mechanism  
is on the to-do list.

Bro generally strives to generate events as soon as it can, so the policy  
script immediately gets a crack at them (and can promptly log if need be).  
connection\_established is generated when the SYN ack is seen (Bro doesn't  
wait for the final ack completing the three-way handshake, because often it  
won't ever see it because of use of a SYN/FIN/RST filter). Likewise,  
connection\_rejected is generated as soon as the RST is seen. However,  
connection\_attempt is only generated five minutes after the first SYN  
is seen, to give the connection time to first become established.  
Bro could generate this sooner, or make it tunable, or generate a  
connection\_first\_packet event on the first packet (if the policy  
script includes a handler). I'd be interested in hearing from folks  
who find they'd like that - it's an easy addition.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/how-to-control-when-bro-logs-events/27/2 "2022-05-06T15:36:03Z")

</div>


