# http.log mime\_type miss match

**URL:** <https://community.zeek.org/t/http-log-mime-type-miss-match/3144>\
**Category:** Zeek\
**Created:** [June 11, 2014, 8:58am UTC](https://community.zeek.org/t/http-log-mime-type-miss-match/3144 "2014-06-11T08:58:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![user13](https://avatars.discourse-cdn.com/v4/letter/u/a88e57/32.png) [@user13](https://community.zeek.org/u/user13)\
**Post date:** [June 11, 2014, 8:58am UTC](https://community.zeek.org/t/http-log-mime-type-miss-match/3144/1 "2014-06-11T08:58:59Z")

</div>

Hi every one

I am testing some of the music streaming service and found one of them miss matching mime\_type compare to Wireshark.

wireshark’s type is audio/mpeg but bro http.log is text/plain

is it bro2.1 is outputting wrong type or do I have to write custom bro script?

this is the bro 2.1 http.log :

Jun 10 09:20:29 6a7HgNEZlOb 192.X.X.X 53796 8.20.213.33 80 1 POST [stream66c-he.grooveshark.com](http://stream66c-he.grooveshark.com) /stream.php [http://grooveshark.com/static/JSQueue\_20140421162423.swf](http://grooveshark.com/static/JSQueue_20140421162423.swf) Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_9\_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 104 10296924 200 OK - - - (empty) - - - text/plain - -

this is the Wireshark screenshot link

[http://ex.narusec.com/data/public/2b0474.php](http://ex.narusec.com/data/public/2b0474.php)

and this is the pcap file (it’s about 733MB)

[http://ex.narusec.com/data/public/23fac8.php](http://ex.narusec.com/data/public/23fac8.php)

---

<div class="post-metadata">

**Author:** ![Josh\_Liburdi](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@Josh\_Liburdi](https://community.zeek.org/u/Josh_Liburdi)\
**Post date:** [June 11, 2014, 11:59am UTC](https://community.zeek.org/t/http-log-mime-type-miss-match/3144/2 "2014-06-11T11:59:37Z")

</div>

I'm not familiar with how Wireshark determines mime type, but that  
version of Bro uses the libmagic database and primarily determines  
mime type by searching for a magic number in the first 1024 bytes of  
the file. It's possible that Bro incorrectly determined the mime type.

Changes were made in Bro 2.3 to move away from the libmagic db.  
Hopefully this means that, in the future, mime type determination will  
be more accurate / extensible. Check the release notes for more info  
on that: [http://www.bro.org/sphinx-git/install/release-notes.html](http://www.bro.org/sphinx-git/install/release-notes.html)

-Josh

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/http-log-mime-type-miss-match/3144/3 "2022-05-06T15:41:50Z")

</div>


