# how to realize alert in real time

**URL:** <https://community.zeek.org/t/how-to-realize-alert-in-real-time/257>\
**Category:** Zeek\
**Created:** [June 22, 2002, 6:39am UTC](https://community.zeek.org/t/how-to-realize-alert-in-real-time/257 "2002-06-22T06:39:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [June 22, 2002, 6:39am UTC](https://community.zeek.org/t/how-to-realize-alert-in-real-time/257/1 "2002-06-22T06:39:40Z")

</div>

> According to some literature, "bro can make intrusion announcement in  
> real time", but when I try to run bro, I don't find how to realize this  
> function, I only can create some logfiles.

The "log" statement logs a string via syslog().  
The system() function invokes an arbitrary shell command.

> And, if it do this as said,  
> what is the form of alert?

Just a string. Recently, Umesh Shankar has added a framework of "attributes",  
i.e., additional information associated with values, and the main impetus  
behind this has been to add structure to Bro alerts, since that's really  
needed so they can be better filtered/post-processed/etc. It will be in  
the next major release of Bro, which I'm aiming to have out in August.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/how-to-realize-alert-in-real-time/257/2 "2022-05-06T15:36:31Z")

</div>


