# How to correctly understand missed\_bytes?

**URL:** <https://community.zeek.org/t/how-to-correctly-understand-missed-bytes/7080>\
**Category:** Zeek\
**Created:** [July 8, 2023, 5:58am UTC](https://community.zeek.org/t/how-to-correctly-understand-missed-bytes/7080 "2023-07-08T05:58:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nick](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@nick](https://community.zeek.org/u/nick)\
**Post date:** [July 8, 2023, 5:58am UTC](https://community.zeek.org/t/how-to-correctly-understand-missed-bytes/7080/1 "2023-07-08T05:58:33Z")

</div>

Hi! Dear team,  
I do some experiments and have some problems.  
case1: ‘orig\_bytes’: 0, ‘resp\_bytes’: 4294967295,‘missed\_bytes’: 5380689127. i.e.,orig\_bytes+resp\_bytes \<missed\_bytes  
case2：‘orig\_bytes’: 6055, ‘resp\_bytes’: 9863, ‘missed\_bytes’: 10897. i.e.,orig\_bytes+resp\_bytes\>missed\_bytes,and orig\_bytes\<missed\_bytes,resp\_bytes\<missed\_bytes  
case3: ‘orig\_bytes’: 0, ‘resp\_bytes’: 0,‘missed\_bytes’: 1787782494  
case4:‘orig\_bytes’: 0, ‘resp\_bytes’: 18419023091,‘missed\_bytes’: 18419023091,i.e.,resp\_bytes=missed\_bytes  
case5:‘orig\_bytes’: 1957083349, ‘resp\_bytes’: 0, ‘missed\_bytes’: 1957083349, i.e.,orig\_bytes=missed\_bytes  
…some other caces.  
I want to know if i can get the exact orig\_bytes and resp\_bytes. If can not, How to correctly understand missed\_bytes, orig\_bytes, resp\_bytes. I know orig\_bytes and resp\_bytes are got from tcp seq. I’m dying to know the real outbound byte count and inbound byte count. Because that is a critical indicator to estimate data breach volume.  
I would greatly appreciate a prompt response from you. Your timely assistance would be highly valued.  
Thanks！  
Nick

---

<div class="post-metadata">

**Author:** ![Christian](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/christian/32/593_2.png) [@Christian](https://community.zeek.org/u/Christian)\
**Post date:** [July 18, 2023, 1:25am UTC](https://community.zeek.org/t/how-to-correctly-understand-missed-bytes/7080/2 "2023-07-18T01:25:55Z")

</div>

I think you’re seeing evidence of capture loss in some of those cases that are confusing Zeek. For example, a missed bytes value of 5380689127 is over 5GB. Note that `missed_bytes` simply accounts for content gaps in either direction, see [here](https://github.com/zeek/zeek/blob/master/scripts/base/protocols/conn/main.zeek#L285-L290).

For an alternative view at byte counts you could explore the `orig_ip_bytes` and `resp_ip_bytes` fields.

Best,  
Christian

---

<div class="post-metadata">

**Author:** ![nick](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@nick](https://community.zeek.org/u/nick)\
**Post date:** [August 15, 2023, 2:10am UTC](https://community.zeek.org/t/how-to-correctly-understand-missed-bytes/7080/3 "2023-08-15T02:10:02Z")

</div>

Thanks a lot. I have new question. The explanation of the conn\_state value ‘s1’ in the Zeek documentation is “Connection established, not terminated.” It also mentions that it has a “0 byte count.” However, in the logs I captured that contain the ‘s1’ flag, the byte count is not zero. Why does the SF explanation in the sf state mention that the byte count for ‘s1’ must be zero? Is this explanation incorrect?

---

<div class="post-metadata">

**Author:** ![nick](https://avatars.discourse-cdn.com/v4/letter/n/f9ae1b/32.png) [@nick](https://community.zeek.org/u/nick)\
**Post date:** [August 15, 2023, 2:18am UTC](https://community.zeek.org/t/how-to-correctly-understand-missed-bytes/7080/4 "2023-08-15T02:18:01Z")

</div>

That confuses me. I want to exactly understand S1.
