# IGMP analyzer

**URL:** <https://community.zeek.org/t/igmp-analyzer/1358>\
**Category:** Zeek\
**Created:** [July 15, 2008, 2:24pm UTC](https://community.zeek.org/t/igmp-analyzer/1358 "2008-07-15T14:24:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![uday\_chekuri](https://avatars.discourse-cdn.com/v4/letter/u/e480ec/32.png) [@uday\_chekuri](https://community.zeek.org/u/uday_chekuri)\
**Post date:** [July 15, 2008, 2:24pm UTC](https://community.zeek.org/t/igmp-analyzer/1358/1 "2008-07-15T14:24:19Z")

</div>

I am just wondering whether the IGMP analyzer is available in the new version of bro 1.3.2???

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [July 15, 2008, 2:44pm UTC](https://community.zeek.org/t/igmp-analyzer/1358/2 "2008-07-15T14:44:51Z")

</div>

> I am just wondering whether the IGMP analyzer is available in the new  
> version of bro 1.3.2???

What IGMP analyzer are you referring to?

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![uday\_chekuri](https://avatars.discourse-cdn.com/v4/letter/u/e480ec/32.png) [@uday\_chekuri](https://community.zeek.org/u/uday_chekuri)\
**Post date:** [July 23, 2008, 10:06pm UTC](https://community.zeek.org/t/igmp-analyzer/1358/3 "2008-07-23T22:06:08Z")

</div>

I am having trace file containg an attack related to bid 514.

DOS IGMP dos attack sid 1:273:8 bid 514;"

snort is showing up but the converted snort2bro rule  
signature s2b-273-8 {  
header ip[9:1] == 2  
event “DOS IGMP dos attack sid 1:273:8 bid 514;”  
header ip[6:1] & 224 == 32  
}

is not throwing any alerts.

Thats the reason why I asked

Thanks,  
UC

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [July 23, 2008, 10:18pm UTC](https://community.zeek.org/t/igmp-analyzer/1358/4 "2008-07-23T22:18:29Z")

</div>

> I am having trace file containg an attack related to bid 514.

Can you send it?

> snort is showing up but the converted snort2bro rule  
> signature s2b-273-8 {  
> &nbsp;&nbsp;header ip[9:1] == 2  
> &nbsp;&nbsp;event "DOS IGMP dos attack sid 1:273:8 bid 514;"  
> &nbsp;&nbsp;header ip[6:1] & 224 == 32  
> }

Note, we don't term this an IGMP \*analyzer\*, just an imported Snort rule.  
We don't support such rules other than in terms of fixing problems they  
exhibit that are due to Bro's underlying signature-matcher. (That is, we  
don't vouch for the Snort rules, nor try to clean them up, nor support the  
snort2bro translation utility.)

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/igmp-analyzer/1358/5 "2022-05-06T15:38:36Z")

</div>


