# How to get anything into c$service

**URL:** <https://community.zeek.org/t/how-to-get-anything-into-c-service/1228>\
**Category:** Zeek\
**Created:** [September 22, 2007, 1:52am UTC](https://community.zeek.org/t/how-to-get-anything-into-c-service/1228 "2007-09-22T01:52:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christian\_Kreibich3](https://avatars.discourse-cdn.com/v4/letter/c/4af34b/32.png) [@Christian\_Kreibich3](https://community.zeek.org/u/Christian_Kreibich3)\
**Post date:** [September 22, 2007, 1:52am UTC](https://community.zeek.org/t/how-to-get-anything-into-c-service/1228/1 "2007-09-22T01:52:18Z")

</div>

Hi,

I seem to have lost the mojo for getting any services to show up in the  
connection records' service set. I have:

&nbsp;&nbsp;@load conn  
&nbsp;&nbsp;redef dpd\_conn\_logs = T;

However, the service set remains empty in new\_connection and  
connection\_finished events. I guess that makes sense for the former  
event, but not the latter, so what else do I need?

(Basically, I'd like to have a reliable way to generate content in  
c$service for the broconn Broccoli test case.)

Cheers,  
Christian

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [September 22, 2007, 6:23pm UTC](https://community.zeek.org/t/how-to-get-anything-into-c-service/1228/2 "2007-09-22T18:23:27Z")

</div>

"services" is set at a few locations whenever some script believes  
it has recognized a service. Most importantly that's DPD's protocol  
detection[1] but also, e.g., ftp-data and portmapper connections.

The crucial point is that you need to have some analyzer running  
which takes the decision. Assuming dpd\_conn\_logs=T, I get for  
example service={HTTP} for HTTP sessions once I load http-request.

Robin

[1] Also applies to standard ports, i.e., even without running the  
DPD signatures.

---

<div class="post-metadata">

**Author:** ![Christian\_Kreibich3](https://avatars.discourse-cdn.com/v4/letter/c/4af34b/32.png) [@Christian\_Kreibich3](https://community.zeek.org/u/Christian_Kreibich3)\
**Post date:** [September 24, 2007, 5:51am UTC](https://community.zeek.org/t/how-to-get-anything-into-c-service/1228/3 "2007-09-24T05:51:53Z")

</div>

Thanks! Mhmm ... I don't quite see this. When I use

&nbsp;&nbsp;@load conn  
&nbsp;&nbsp;@load http-request  
&nbsp;&nbsp;redef dpd\_conn\_logs = T;

then I no longer seem to get connection\_finished events(!), despite  
seeing the teardown on the wire. I do however see  
connection\_state\_remove, but without anything in c$service. When I use

&nbsp;&nbsp;@load conn  
&nbsp;&nbsp;@load dpd  
&nbsp;&nbsp;redef dpd\_conn\_logs = T;

all is well: I get both connection\_finished and connection\_state\_remove,  
and both carry HTTP in c$service (since in that case the capture filter  
ends up being "tcp or udp or icmp").

Cheers,  
Christian

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [September 24, 2007, 6:17am UTC](https://community.zeek.org/t/how-to-get-anything-into-c-service/1228/4 "2007-09-24T06:17:13Z")

</div>

> &nbsp;&nbsp;@load conn

[...]

> then I no longer seem to get connection\_finished events(!), despite

Does loading tcp.bro instead of conn.bro help?

> &nbsp;&nbsp;@load conn  
> &nbsp;&nbsp;@load dpd  
> &nbsp;&nbsp;redef dpd\_conn\_logs = T;
> 
> all is well: I get both connection\_finished and connection\_state\_remove,  
> and both carry HTTP in c$service (since in that case the capture filter  
> ends up being "tcp or udp or icmp").

My last reply actually simplified things a bit, sorry. For services  
added via the DPD mechanism (i.e., verifying the presence of the  
protocol by having the analyzer parse it), this is what is needed:

- the (core) analyzer needs to see the packets. That's the case with  
Bro's fall-back default "tcp or udp or icmp" but not anymore once  
you load any script which modifies the default (e.g., tcp.bro). If  
so, you either need to set the filter manually or load the  
corresponding analyzer script which then makes sure the packets are  
included. That's actually why I refered to http-request.bro

- you need to load conn.bro (which almost always gets pulled in by  
some other script anyway). conn.bro has the handler for the  
protocol\_confirmation() event, which adds the entry to the service  
field once an analyzer believes it's indeed its protocol.

For other services (i.e., non-DPD) the corresponding script sets the  
services. E.g., ftp.bro adds an entry "ftp-data" to services for  
data sessions.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/how-to-get-anything-into-c-service/1228/5 "2022-05-06T15:38:21Z")

</div>


