# Issue with SumStats and tcpdump filters?

**URL:** https://community.zeek.org/t/issue-with-sumstats-and-tcpdump-filters/7098
**Category:** Zeek
**Created:** [July 26, 2023, 8:00pm UTC](https://community.zeek.org/t/issue-with-sumstats-and-tcpdump-filters/7098 "2023-07-26T20:00:01Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![GaryR](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/garyr/32/688_2.png) [@GaryR](https://community.zeek.org/u/GaryR)
#### Post date: [July 26, 2023, 8:00pm UTC](https://community.zeek.org/t/issue-with-sumstats-and-tcpdump-filters/7098/1 "2023-07-26T20:00:01Z")

</div>

I am writing a zeek script similar to one of the [samples](https://docs.zeek.org/en/master/frameworks/sumstats.html), and it works fine when I don’t specify a tcpdump filter but not when I do. My filter looks something like `tcp and dst host 1.2.3.4 and dst port 80` where `1.2.3.4` is an IP address that is on the interface zeek is listening on, but even simpler filters don’t work. Before I dig into the code, is there a reason this doesn’t work?
