# How to generate the alerts directly?

**URL:** <https://community.zeek.org/t/how-to-generate-the-alerts-directly/588>\
**Category:** Zeek\
**Created:** [September 20, 2004, 5:50am UTC](https://community.zeek.org/t/how-to-generate-the-alerts-directly/588 "2004-09-20T05:50:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [September 20, 2004, 5:50am UTC](https://community.zeek.org/t/how-to-generate-the-alerts-directly/588/1 "2004-09-20T05:50:35Z")

</div>

> &nbsp;&nbsp;&nbsp;&nbsp;# ./bro -r /home/zhangwei/bro0907.dump  
> &nbsp;&nbsp;&nbsp;&nbsp;generate the "alerts" as following:  
> &nbsp;&nbsp;&nbsp;&nbsp;1094539834.607852 weird: spontaneous\_FIN  
> 1094539847.830742 weird: possible\_split\_routing

These are not "alerts" but rather "weird"'s - that is, messages that  
reflect unusual/broken activity.

> First,are the terms which i use right,such as "event" ,"alerts"?

Per the above, those are "weird"'s. Perhaps there's a better name to use;  
in the future, they might be merged with the "NOTICE" framework (which  
is called ALERT in the present release, but this changes with the next  
release).

> Second,whether can I generate those alerts directly?  
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;If can,which command should i use? Or how to modify the source code?

I don't know what you mean by "directly" here.

If you mean in your policy script, you do so by calling ALERT().

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/how-to-generate-the-alerts-directly/588/2 "2022-05-06T15:37:10Z")

</div>


