# How to set logging path by interface

**URL:** <https://community.zeek.org/t/how-to-set-logging-path-by-interface/6659>\
**Category:** Zeek\
**Created:** [August 23, 2022, 6:14am UTC](https://community.zeek.org/t/how-to-set-logging-path-by-interface/6659 "2022-08-23T06:14:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raphael98](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@raphael98](https://community.zeek.org/u/raphael98)\
**Post date:** [August 23, 2022, 6:14am UTC](https://community.zeek.org/t/how-to-set-logging-path-by-interface/6659/1 "2022-08-23T06:14:47Z")

</div>

Hello,

We set up and operate two interfaces on one zeek host.

By integrating two interfaces, it is burdensome to classify logs.

What should I do if I want to generate logs in different paths for different interfaces?

When I was running 2 instances on one zeek host, Logger was failing to run properly due to port duplication running issues.

---

<div class="post-metadata">

**Author:** ![awelzel](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/awelzel/32/609_2.png) [@awelzel](https://community.zeek.org/u/awelzel)\
**Post date:** [August 23, 2022, 5:03pm UTC](https://community.zeek.org/t/how-to-set-logging-path-by-interface/6659/2 "2022-08-23T17:03:54Z")

</div>

> [@raphael98](#):
>
> When I was running 2 instances on one zeek host, Logger was failing to run properly due to port duplication running issues.

It might be easier to sort out the port conflict(s). Are you using zeekctl or setting up clusters by hand?

Otherwise, if you have the interface name available within Zeek scripting you can use the path\_func for logging filters and prefix the paths with the interface name [1].

@JustinAzoff (or someone else) - do you maybe have a canned solution for this? Know an easy way to get the monitoring interface name outside of of using `zeek_args()` trickery, using `zeek interfaces="eth0"` or setting an environment variable and using `getenv()`?

[1] [Logging Framework — Book of Zeek (v5.0.0)](https://docs.zeek.org/en/v5.0.0/frameworks/logging.html#determine-log-path-dynamically)

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [August 23, 2022, 5:50pm UTC](https://community.zeek.org/t/how-to-set-logging-path-by-interface/6659/3 "2022-08-23T17:50:42Z")

</div>

The easiest way to do different things on different workers is to use the `SitePolicyScripts` option to load a different set of scripts on each process, instead of everything just loading `local.zeek`. You could use a script that sets up a log extension callback to add interface specific fields to each log.

You _could_ probably do it by parsing the arguments to pull out the interface, but just setting `SitePolicyScripts` to `local.zeek eth0.zeek` or `local.zeek eth1.zeek` is a lot simpler.

You can fix the logger port conflict by setting `ZeekPort` to something different in each install, otherwise all of the processes in each cluster will use exactly the same ports.

---

<div class="post-metadata">

**Author:** ![raphael98](https://avatars.discourse-cdn.com/v4/letter/r/bbce88/32.png) [@raphael98](https://community.zeek.org/u/raphael98)\
**Post date:** [August 25, 2022, 7:08am UTC](https://community.zeek.org/t/how-to-set-logging-path-by-interface/6659/4 "2022-08-25T07:08:28Z")

</div>

How can I change the logger port while installing zeek?

Are there any port change options available for the zeek install command?

Thanks for your kind reply.
