# HTTP Post data

**URL:** <https://community.zeek.org/t/http-post-data/2256>\
**Category:** Zeek\
**Created:** [March 8, 2012, 3:03pm UTC](https://community.zeek.org/t/http-post-data/2256 "2012-03-08T15:03:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Will\_Havlovick](https://avatars.discourse-cdn.com/v4/letter/w/839c29/32.png) [@Will\_Havlovick](https://community.zeek.org/u/Will_Havlovick)\
**Post date:** [March 8, 2012, 3:03pm UTC](https://community.zeek.org/t/http-post-data/2256/1 "2012-03-08T15:03:47Z")

</div>

Hi all,

Is there a way to write the data(body) of a HTTP Post request to the http.log? Or another log file?

Thank you,

Will

---

<div class="post-metadata">

**Author:** ![Matthias\_Vallentin1](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/matthias_vallentin1/32/596_2.png) [@Matthias\_Vallentin1](https://community.zeek.org/u/Matthias_Vallentin1)\
**Post date:** [March 8, 2012, 5:29pm UTC](https://community.zeek.org/t/http-post-data/2256/2 "2012-03-08T17:29:54Z")

</div>

> Is there a way to write the data(body) of a HTTP Post request to the  
> http.log? Or another log file?

Yes, that's possible. You would have to reassemble the data from the  
body across the http\_entity\_\* events. Here is an example of how one  
could do it:

> <https://github.com/mavam/brospects/blob/master/bro/bodies.bro>

&nbsp;&nbsp;&nbsp;&nbsp;Matthias

---

<div class="post-metadata">

**Author:** ![Will\_Havlovick](https://avatars.discourse-cdn.com/v4/letter/w/839c29/32.png) [@Will\_Havlovick](https://community.zeek.org/u/Will_Havlovick)\
**Post date:** [March 9, 2012, 2:35pm UTC](https://community.zeek.org/t/http-post-data/2256/3 "2012-03-09T14:35:03Z")

</div>

Very cool!

I will check this out. We have had some interesting data in forms that are being submitted.

Thank you,

Will

---

<div class="post-metadata">

**Author:** ![Martin\_Holste](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@Martin\_Holste](https://community.zeek.org/u/Martin_Holste)\
**Post date:** [March 9, 2012, 3:57pm UTC](https://community.zeek.org/t/http-post-data/2256/4 "2012-03-09T15:57:37Z")

</div>

This is important enough that the Bro team might want to work on  
something that's on by default. Specifically, many attackers hide  
SQLi in POST params, so auto-extracting and logging some default,  
finite limit of POST params into the HTTP log would be a big win for  
the community.

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [March 9, 2012, 5:11pm UTC](https://community.zeek.org/t/http-post-data/2256/5 "2012-03-09T17:11:26Z")

</div>

Yep, I've done that before and (again!) it's another source of perspective change on network traffic.

Regarding the SQLi detection, I've been planning on extending the SQLi detection script to cover POST data for a long time. Adding post data to the logs is at least easy. I attached a script which will just blindly add a configurable amount of data to your http.log.

I'm not so sure it would ever be turned on by default, but we can certainly consider including a script that does this. It's a load statement away from being enabled that way. 😉

[http-extract-post.bro](https://community.zeek.org/uploads/short-url/9nFWrBtMAnAmNV8md38WTlVtAi8.bro) (574 Bytes)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/http-post-data/2256/6 "2022-05-06T15:40:15Z")

</div>


